native-web-search

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md is a documentation/manifest for a "native-web-search" skill. It describes taking a user query and purpose, invoking a model/native web search, and returning concise summaries with full URLs. There is no code in the provided file that downloads or executes remote binaries, reads credential files, or forwards secrets. The only slightly unusual aspect is the guidance to set PI_AI_MODULE_PATH to a package dist path if module resolution fails — that could let a user (or a misled user) point the runtime at arbitrary local or third-party code, which is a minor supply-chain consideration but not direct malicious behavior in this manifest. Overall I find no direct malicious intent. The primary risks are standard supply-chain/transparency concerns: lack of explicit provider endpoints and the potential for a user to point the runtime at untrusted modules. Recommend verifying the actual search implementation (search.mjs) and the runtime module resolved by PI_AI_MODULE_PATH before trusting it in sensitive environments.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 09:42 AM
Package URL
pkg:socket/skills-sh/mitsuhiko%2Fagent-stuff%2Fnative-web-search%2F@bb6081418a85e910ed4af08066594c0ecedccd5e