octocode-search-skill

Warn

Audited by Socket on Jun 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated purpose and includes meaningful approval gates, but it processes untrusted external skill content and supports transitive installation of third-party skills into agent environments. Main risk is indirect prompt injection and trust extension through marketplace/GitHub skill installs, not confirmed malware or credential theft.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Jun 18, 2026, 04:44 AM
Package URL
pkg:socket/skills-sh/bgauryy%2Foctocode%2Foctocode-search-skill%2F@7c726a9d3ece1f8c5e5500073af850c0c816be7ab0ef1a7083531c541ba284c4
Security Audit — socket — octocode-search-skill