lifecyclemodel-hybrid-search

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/env.md

The fragment demonstrates a typical authenticated request to a Supabase edge function with an API key and region context. While not inherently malicious, it raises supply-chain concerns around key handling, hardcoded-like exposure in the snippet, and reliance on environment overrides which could be misconfigured. Recommend ensuring secure storage of TIANGONG_LCA_APIKEY (not logged or exposed), use short-lived tokens, validate SUPABASE_FUNCTIONS_URL overrides, and minimize key exposure in client environments.

Confidence: 59%Severity: 60%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:59 AM
Package URL
pkg:socket/skills-sh/tiangong-lca%2Fskills%2Flifecyclemodel-hybrid-search%2F@0a4b689e0de790a8860d8ee61fc6dc80e0925f76