bfs-ai-script

Warn

Audited by Socket on Jul 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches the broad AI/media/search functionality, but the skill routes user data and API keys through a local opaque wrapper that sources `~/.zshrc` and invokes an unverifiable CLI/repo. The main risks are supply-chain trust, credential forwarding, and untrusted-content-to-LLM flow rather than confirmed malicious intent.

Confidence: 83%Severity: 84%
Audit Metadata
Analyzed At
Jul 14, 2026, 03:46 PM
Package URL
pkg:socket/skills-sh/bigfatsea%2Fskills%2Fbfs-ai-script%2F@d0a591997b4598228aa1c61296ef8c0f1a7d96c1e9ba4541e43ac70087ecf4d8
Security Audit — socket — bfs-ai-script