sahara-intention-level-skills

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose is plausible, but its actual data flow is not internally trustworthy because all requests and the API key are sent to an undocumented proxy domain instead of a verifiable official Sahara API endpoint. Main risk is credential forwarding and interception through a third-party gateway, not confirmed malware.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:19 AM
Package URL
pkg:socket/skills-sh/SaharaLabsAI%2Fskills%2Fsahara-intention-level-skills%2F@51dcd3e4d0ae3fdaf7b1c755abafa3efc268566c