search-layer

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s main function is legitimate search aggregation, but its actual footprint is broader than a normal search helper. The biggest concerns are credential forwarding through local scripts, configurable third-party endpoint routing for Grok, and recursive processing of untrusted web/GitHub content. No clear malware or covert exfiltration is shown, but the data-flow and trust model are only partially aligned with the stated purpose.

Confidence: 81%Severity: 68%
Audit Metadata
Analyzed At
May 1, 2026, 05:13 AM
Package URL
pkg:socket/skills-sh/aaaaqwq%2Fclaude-code-skills%2Fsearch-layer%2F@222a6ea7752ae45f96da385d2c4afabcdebfdd83