ask-next
Warn
Audited by Socket on Feb 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill fragment is coherently aligned with its stated purpose of retrieving and summarizing Next.js documentation via a remote RAG API. It uses a standard, read-only HTTP request pattern to an external service and does not display credential handling or destructive actions. While it relies on an external service (trust the domain and API), this is typical for knowledge retrieval tools and does not constitute malicious behavior by itself. Overall, the footprint is BENIGN with moderate dependency risk due to the external API.
Confidence: 75%Severity: 75%
Audit Metadata