agno

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and examples are broadly coherent with Agno development, and the core Agno install path is legitimate. The main risk is documentation that encourages running third-party MCP servers via uvx/npx and forwarding environment variables/API keys into those external processes; this is a real supply-chain and credential-forwarding concern, but not confirmed malicious behavior in the skill itself.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Sep 14, 2026, 02:55 PM
Package URL
pkg:socket/skills-sh/delorenj%2Fskills%2Fagno%2F@1b7677d1249fc16579d3fcd60d57b396193419aeec32f21ff22a8232be5523ec
Security Audit — socket — agno