search1api

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS/medium risk. The skill's capabilities mostly match its stated search/research purpose, and the requested API key is proportionate. Main concerns are the pipe-to-shell installer, credential forwarding into an external CLI, and high indirect prompt-injection exposure from arbitrary web content. No clear evidence of credential theft or malicious exfiltration beyond the expected Search1API service flow.

Confidence: 78%Severity: 58%
Audit Metadata
Analyzed At
Apr 2, 2026, 09:33 AM
Package URL
pkg:socket/skills-sh/fatwang2%2Fsearch1api-cli%2Fsearch1api%2F@147165b9f6c0fb519a99c3cbe7b645a9456f5ede