brave-search

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it performs Brave API web/search interactions using an environment-provided API key, supports web/news/image/video searches, and demonstrates typical API usage patterns. There are no evident insecure data flows, credential harvesting, or download/executable patterns. While security risk is not zero (credential exposure potential is limited to the API key and user queries), the design remains proportionate to a web search helper tool and does not introduce abnormal permissions or external data exfiltration chains.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 10:49 PM
Package URL
pkg:socket/skills-sh/sirn%2Fdotfiles%2Fbrave-search%2F@90c0db0f9683f608d86bf3a03f175043e24a589c