lifecyclemodel-hybrid-search

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but it combines remote execution of a mutable npm package with credential forwarding and a user-configurable API endpoint. This looks like a legitimate developer workflow wrapper, not confirmed malware, yet the install and data-flow trust model is only moderately safe.

Confidence: 82%Severity: 53%
Audit Metadata
Analyzed At
Apr 15, 2026, 01:49 PM
Package URL
pkg:socket/skills-sh/tiangong-lca%2Fskills%2Flifecyclemodel-hybrid-search%2F@94fb44ac41fc854321f3a4e08ca455049291daba