agentic-rag-patterns

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/crag-workflow.py

This module implements a CRAG workflow but contains multiple coding mistakes and an accidental demo/example block embedded inside generate_answer. The embedded example will cause unexpected network calls (OpenAI/Tavily) and output if executed, representing a privacy/supply-chain risk. No explicit malicious backdoor or obfuscation is evident, but the file is currently non-functional and unsafe to run unchanged. Recommendation: remove or relocate the example/demo code to a separate example file, fix the incomplete 'system =' stubs and undefined functions (build_crag, example_usage), and review any configured API keys and logging before executing. Treat external LLM and web-search calls as sensitive sinks and audit usage policies.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:06 PM
Package URL
pkg:socket/skills-sh/yonatangross%2Forchestkit%2Fagentic-rag-patterns%2F@f849917a0c7b3c22a45d345129b3c424bd94ba8e