pinecone-assistant

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Based on the SKILL.md content alone, the skill's declared capabilities, required credentials (PINECONE_API_KEY), and execution model are consistent and proportionate for a Pinecone-backed assistant. There are no immediate indicators of malicious behavior in this document (no untrusted downloads, no third-party proxy endpoints, no hardcoded secrets). However, the real security posture depends on the implementation of the referenced scripts (scripts/*.py). I recommend reviewing those scripts to confirm they: (1) call official Pinecone endpoints, (2) do not exfiltrate data to other domains, (3) do not read unrelated credential files, and (4) avoid executing arbitrary untrusted code. Without those scripts, residual supply-chain risk remains moderate.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:58 AM
Package URL
pkg:socket/skills-sh/pinecone-io%2Fskills%2Fpinecone-assistant%2F@10183c2f925fb78a5fda9449bc23d1f6c9d1a17b