vector-db-init
Fail
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The vector-db-init skill presents a coherent and proportionate footprint for its stated purpose: it installs Python dependencies via pip, and configures local profiles to prepare for vector DB usage. The data flows are primarily local (config files) with standard PyPI network activity. Some improvements could include explicit version pinning and integrity verification for dependencies to strengthen supply-chain security. Overall, the skill is BENIGN with moderate security considerations around dependency provenance and reproducibility, staying within expected boundaries for developer tooling.
Confidence: 98%
Audit Metadata