ai-sdk

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment is primarily documentation and usage guidance for an AI SDK. There are no embedded malicious actions, credentials, or destructive operations within the fragment itself. The main risk is the inclusion of an external curl model-list fetch as a runtime guidance, which could enable outbound network calls if misused by an automation agent. Given the absence of harmful intent in the fragment and the context of developer guidance, the overall security posture is BENIGN with a MEDIUM caution due to the external network instruction that, if executed automatically, could constitute an unintended data-leak vector. Recommend reviewers ensure any automated agent that follows this guidance properly scopes and authenticates outbound requests and that such model-list fetches are opt-in and auditable.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 06:59 AM
Package URL
pkg:socket/skills-sh/wenerme%2Fai%2Fai-sdk%2F@d8e09e2796e2a04a9c7f7cc8c5bbab8da76a77d9