pipes-new-indexer

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s overall purpose is coherent for blockchain indexer scaffolding, and its database/file actions mostly fit that purpose. The main concern is install trust: the skill published by subsquid relies on an unpinned third-party npm CLI (@iankressin/pipes-cli@latest) without establishing an official publisher relationship, creating medium-high supply-chain risk. Credential handling is proportionate but sensitive, and the mandated external research adds some prompt-injection exposure.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:59 PM
Package URL
pkg:socket/skills-sh/subsquid-labs%2Fagent-skills%2Fpipes-new-indexer%2F@4ca1e58a021e3b54f55debcd709fba9f5b5977c4