youdotcom-cli

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

No malicious code or supply-chain download-execute patterns were found. The skill is a Bash-based wrapper that calls official You.com APIs (api.you.com) and a related content indexing host (ydc-index.io) using curl and jq. The required API key is read from an environment variable and sent only to the declared endpoints. Primary risks are operational: accidental disclosure of YDC_API_KEY, and improper execution of untrusted fetched content if users/agents ignore the guidance to treat responses as untrusted. Validate that ydc-index.io is an official/expected domain for your use case before providing keys.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 05:09 AM
Package URL
pkg:socket/skills-sh/youdotcom-oss%2Fagent-skills%2Fyoudotcom-cli%2F@87211ed93f52f2466d0b35c2b8e215677181359d