ai-rag-pipeline

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The code fragment describes a coherent RAG orchestration with multiple external tools and a bootstrap installer. While functionally plausible for grounded, cited responses, the download-and-execute installer from a remote domain and broad tool permissions introduce non-trivial supply-chain and data-flow risks. Strengthening provenance, signing, and access controls is essential before deployment in production environments.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 12:32 PM
Package URL
pkg:socket/skills-sh/tul-sh%2Fskills%2Fai-rag-pipeline%2F@7e1fb7e75fa06d2526dcc700e8a342d9540c9344