pachca-search

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Pachca-search skill presents a coherent and proportionate implementation for its stated goal of full-text search across employees, chats, and messages via a CLI. It relies on standard, official package sources (npm registry) and uses user-controlled credentials (PACHCA_TOKEN) to access Pachca endpoints. The data flow is user input -> CLI -> Pachca API -> CLI output, with no evident misuse of credentials or external data sinks beyond the service. Overall risk is low to moderate (benign with normal CLI authorization patterns); no indicators of malicious activity or dangerous supply-chain behavior are detected.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 04:05 PM
Package URL
pkg:socket/skills-sh/pachca%2Fopenapi%2Fpachca-search%2F@136983a4f2a7d97077c520afe6d95942610e03f2