NYC

langchain

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Benign overall documentation with a notable caution: an example demonstrates using eval in a Tool, which is a risky pattern and should be addressed before reuse. No hidden or malicious data flows are present in this fragment; credential handling is shown only as standard environment variables in examples. Recommend replacing eval-based example with a safe alternative in any real implementation.

Confidence: 29%Severity: 40%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:45 PM
Package URL
pkg:socket/skills-sh/ovachiever%2Fdroid-tings%2Flangchain%2F@910b4ce4a6d756e3c37303f8c45a79ec8282d1d1