ydc-openai-agent-sdk-integration

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment is an integration scaffold describing how to wire OpenAI Agents SDK with You.com MCP via Hosted or Streamable HTTP transports. It consistently treats external MCP results as untrusted data, requires environment-based credentials, and uses standard, reputable package sources. There are no explicit malicious actions, hidden backdoors, or hardcoded secrets. The data flows align with the stated purpose (external MCP calls authenticated with API keys). Because it is a template that would run against external services when properly configured, it presents typical security considerations (credential protection, untrusted content handling, network exposure) but does not exhibit malicious intent or payloads. Overall, the risk is low-to-medium due to external network interactions and untrusted content handling, but nothing indicates deliberate harm.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 05:08 AM
Package URL
pkg:socket/skills-sh/youdotcom-oss%2Fagent-skills%2Fydc-openai-agent-sdk-integration%2F@102693ae3cd58bd8de9cd8f4e1548c6783d74d62