algolia-cli

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities fit its stated Algolia admin purpose, and most credential/data flows are proportionate. The main issue is install trust: Linux setup uses non-official repo instructions that disable package verification, and the Windows package name does not cleanly match official docs. This is not confirmed malware, but it is a medium-high risk skill because it installs external tooling and can perform destructive account/index operations non-interactively with high-privilege credentials.

Confidence: 91%Severity: 68%
AnomalyLOW
references/getting-started.md

The material is ordinary Algolia CLI setup documentation and contains no demonstrated malware or data theft behavior. The main security concern is that the Linux examples disable package signature verification, increasing the risk of installing tampered packages; users should prefer signed repositories and verify package integrity before using these commands.

Confidence: 98%Severity: 56%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:42 AM
Package URL
pkg:socket/skills-sh/algolia%2Fskills%2Falgolia-cli%2F@e2ac24ea505dea7da45531146cf9188851d2950222e3f04f91260be7008a42fb
Security Audit — socket — algolia-cli