grok-search

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but its actual execution depends on an unidentified Grok Search MCP surface that is not verified as official xAI from the provided evidence. The main risk is trust and credential routing: a plausible third-party MCP implementation can receive XAI_API_KEY and process arbitrary web content, creating medium-high supply-chain and prompt-injection risk even without clear evidence of outright malware.

Confidence: 88%Severity: 81%
Audit Metadata
Analyzed At
May 6, 2026, 07:21 AM
Package URL
pkg:socket/skills-sh/ry-run%2Frun-skills%2Fgrok-search%2F@26a33ca5330415dc84582e123259b25218972a97