enable-semantic-search

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and local data flow are mostly coherent, but the install trust is weakened by two factors: official-but-unpinned curl|bash for Bun and, more importantly, installing QMD from a GitHub repo spec instead of the maintainer's documented npm package. This looks more like risky setup hygiene than confirmed malware, with medium/high supply-chain risk but no clear credential theft or exfiltration behavior.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
May 20, 2026, 12:43 AM
Package URL
pkg:socket/skills-sh/davekilleen%2FDex%2Fenable-semantic-search%2F@953180a9a0a529aea147bb85404f52ce4273ec67
Security Audit — socket — enable-semantic-search