flow-hybrid-search

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the skill relies on executing an unpinned external CLI and forwards the API key through that CLI instead of documenting direct calls to the Supabase endpoint. With no supplied provenance evidence for the npm package or publisher relationship, the install/execution trust is only partially justified.

Confidence: 79%Severity: 66%
Audit Metadata
Analyzed At
Apr 15, 2026, 01:49 PM
Package URL
pkg:socket/skills-sh/tiangong-lca%2Fskills%2Fflow-hybrid-search%2F@29b53aca8ffbfb9c66d51e3269006df1be300eb3