local-ai-app-integration

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Security
SecurityMEDIUM
evals/evals.json

The evaluation payload indicates high-risk intent around local/offline model deployment, vendor binaries, and removal of authentication barriers. While the content is a data structure describing prompts (not executed code), adopting these prompts in tooling could enable supply-chain manipulation, data leakage, or backdoors. Recommend strict governance, code review, and explicit authorization before enabling offline/inlined inference or vendor binaries in any consumer-facing or enterprise product.

Confidence: 52%Severity: 78%
Audit Metadata
Analyzed At
Aug 26, 2026, 10:58 AM
Package URL
pkg:socket/skills-sh/amd%2Fskills%2Flocal-ai-app-integration%2F@a521af1d7bf4c0efb456a3168db1d73c956c45b43cb5b3572b698427978e4e32
Security Audit — socket — local-ai-app-integration