ydc-langchain-integration
Fail
Audited by Socket on Mar 4, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The fragment is coherently aligned with its stated purpose as integration documentation for LangChain.js and You.com tools. It fluxes through standard, expected channels (environment variable for API key, official package usage, web tool results) and includes appropriate security guidance for handling untrusted web content. It does not contain executable payloads, hidden exfiltration, or suspicious credential harvesting patterns. Overall, the material is benign in intent and scope, with moderate security risk arising from the need to securely manage API keys and trust boundaries when using web-derived tool outputs.
Confidence: 95%Severity: 90%
Audit Metadata