AgentDB Advanced Features

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is documentation for advanced distributed features of an AgentDB-like system. The content is plausible and mostly benign as documentation, but it contains multiple supply-chain and network-surface risks: it encourages running code via npx (transitive execution), instructs opening UDP ports and syncing data to arbitrary peers, and does not provide concrete peer authentication or key management guidance. Those factors make misuse or misconfiguration capable of enabling data exfiltration to attacker-controlled peers or executing untrusted CLI packages with access to local DB files. No explicit backdoor, hardcoded credentials, or obfuscated executable payloads are present in the provided text. Recommended actions before use: verify the provenance of the agentdb/agentic-flow package, require mutual TLS or authenticated peers for QUIC sync, restrict peer lists to trusted hosts, and review any code run via npx before executing.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fagentdb-advanced-features%2F@1a85d1470ed0d8527c41a6ac0571bf600a367818