GraphQL Data Federation Agent

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the fragment is mostly a marketplace installer for a remote skill, not a transparent GraphQL federation implementation. The biggest issue is transitive skill installation plus provenance mismatch between the claimed source (`graphql/graphql-js`) and the actual distributors (`agentskillexchange/skills`, `clawhub`). No direct credential theft or exfiltration is shown in the provided text, so this is better classified as a supply-chain and trust-boundary risk than confirmed malware.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fgraphql-data-federation-agent%2F@009ea8253c5a9b37cc821e85837d129f56843d32