process-hybrid-search

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Likely benign but with medium security risk. The skill's capabilities align with its stated purpose of testing a Supabase hybrid search function, yet it relies on executing a mutable external CLI via npx and forwards API credentials through that CLI, with a configurable endpoint that could redirect those credentials if misconfigured.

Confidence: 81%Severity: 52%
Audit Metadata
Analyzed At
Apr 15, 2026, 01:50 PM
Package URL
pkg:socket/skills-sh/tiangong-lca%2Fskills%2Fprocess-hybrid-search%2F@acb2ffe3e7b7a04aa29510cd7fbd127b722149a4