code-search

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent for code search, but the execution model depends on an unpinned external package fetched at runtime with no verified publisher relationship for `codebasesearch`. There is no clear credential theft or exfiltration behavior, yet install/execution trust is materially weak for a skill that must be relied on for all code exploration.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:30 PM
Package URL
pkg:socket/skills-sh/anentrypoint%2Fplugforge%2Fcode-search%2F@9401881714971a6cedfe3b82552226fdd0eb0aca
Security Audit — socket — code-search