vector-db-init

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The vector-db-init skill presents a coherent and proportionate footprint for its stated purpose: it installs Python dependencies via pip, and configures local profiles to prepare for vector DB usage. The data flows are primarily local (config files) with standard PyPI network activity. Some improvements could include explicit version pinning and integrity verification for dependencies to strengthen supply-chain security. Overall, the skill is BENIGN with moderate security considerations around dependency provenance and reproducibility, staying within expected boundaries for developer tooling.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 06:49 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fvector-db-init%2F@aa5cefd1475efce1969bac7218e261ae22e6f05a