algolia-cli
Audited by Socket on Sep 15, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the skill's capabilities fit its stated Algolia admin purpose, and most credential/data flows are proportionate. The main issue is install trust: Linux setup uses non-official repo instructions that disable package verification, and the Windows package name does not cleanly match official docs. This is not confirmed malware, but it is a medium-high risk skill because it installs external tooling and can perform destructive account/index operations non-interactively with high-privilege credentials.
The material is ordinary Algolia CLI setup documentation and contains no demonstrated malware or data theft behavior. The main security concern is that the Linux examples disable package signature verification, increasing the risk of installing tampered packages; users should prefer signed repositories and verify package integrity before using these commands.