ddg-search
Warn
Audited by Socket on Feb 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The improved assessment confirms that the skill is a straightforward DuckDuckGo search helper without API keys. The primary risks relate to privacy (query leakage to a third party) and potential abuse (rate limiting, input validation). The fragment does not show code-level issues, but a full review should examine search.py for input sanitization, rate limiting, and safe parsing of results. Overall, the footprint is benign given the information, with recommended follow-ups focusing on privacy and input handling.
Confidence: 65%Severity: 58%
Audit Metadata