searxng-search

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's described purpose (web search via a self-hosted SearXNG) aligns with its configuration-driven approach. Data flows involve querying a configured API endpoint with optional credentials, and returning results to the user. While credentials are stored and used for API authentication, this is proportional to the task. No evident arbitrary downloads, covert data exfiltration, or autonomous real-world actions are present. Overall risk is low to moderate, driven primarily by credential handling and environment-based token sourcing. Recommend ensuring config files are securely stored and that environment variables used for tokens are tightly scoped.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 12:37 PM
Package URL
pkg:socket/skills-sh/XYenon%2Fagents%2Fsearxng-search%2F@db564af6907d73a75fe57e1ddb571583f3d08c80