pipes-new-indexer
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s overall purpose is coherent for blockchain indexer scaffolding, and its database/file actions mostly fit that purpose. The main concern is install trust: the skill published by subsquid relies on an unpinned third-party npm CLI (@iankressin/pipes-cli@latest) without establishing an official publisher relationship, creating medium-high supply-chain risk. Credential handling is proportionate but sensitive, and the mandated external research adds some prompt-injection exposure.
Confidence: 81%Severity: 72%
Audit Metadata