enable-semantic-search
Warn
Audited by Socket on May 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose and local data flow are mostly coherent, but the install trust is weakened by two factors: official-but-unpinned curl|bash for Bun and, more importantly, installing QMD from a GitHub repo spec instead of the maintainer's documented npm package. This looks more like risky setup hygiene than confirmed malware, with medium/high supply-chain risk but no clear credential theft or exfiltration behavior.
Confidence: 89%Severity: 72%
Audit Metadata