process-hybrid-search

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/request-response.md

This API fragment outlines a standard authenticated endpoint for a hybrid search using a database RPC and an embedding step. While no explicit malicious activity is visible, there are clear security concerns around secret handling, input sanitization, and exposure risk through logs and external RPCs. The overall risk is moderate with actionable mitigations focusing on parameterization, secrets management, input validation, and robust logging practices to reduce the chance of data leakage or injection.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 3, 2026, 11:10 PM
Package URL
pkg:socket/skills-sh/tiangong-lca%2Fskills%2Fprocess-hybrid-search%2F@a77485894c5323a579f6544c4c0a1e3d6b388ae7