surrealdb

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
skills/surrealfs/SKILL.md

SUSPICIOUS: the core database-backed virtual filesystem and SurrealDB credential use are internally consistent, but the skill also enables host command execution through pipe commands and includes default telemetry, which broadens data-flow and execution scope beyond a typical filesystem abstraction. Registry-based installs and direct SurrealDB connections keep it below malicious, but it carries medium risk for AI-agent use.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
May 15, 2026, 01:22 PM
Package URL
pkg:socket/skills-sh/24601%2Fsurreal-skills%2Fsurrealdb%2F@57699672de6d2312ac1e4e1e54e0193942354391