log-analytics

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core OpenSearch access is largely aligned with the stated purpose and uses a same-org published MCP package, but the skill still carries medium risk from unpinned uvx execution, credential forwarding to MCP code, an unrelated optional search MCP dependency, and especially the documented SSL verification disablement.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
May 8, 2026, 07:45 AM
Package URL
pkg:socket/skills-sh/opensearch-project%2Fopensearch-agent-skills%2Flog-analytics%2F@c514534aae4eaab740fdc383a18949209a1b31e7