pckle

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated Pinecone affiliation does not match its actual footprint. It requires an undocumented/unverifiable `pckle` binary, installs it via arbitrary-host pipe-to-shell, and forwards Pinecone API credentials and user queries to unverified `pckle` endpoints. This is disproportionate and fails install-trust and data-flow integrity checks.

Confidence: 92%Severity: 90%
Audit Metadata
Analyzed At
Mar 16, 2026, 10:44 AM
Package URL
pkg:socket/skills-sh/pinecone-io%2Fpckle-skill%2Fpckle%2F@e29205bab8778a53d61ad34b41b950951f09bdf9