ai-rag-pipeline
Warn
Audited by Socket on Jun 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated RAG purpose is coherent, but the skill is overpowered for a guide because it grants wildcard Bash, installs other skills, and processes large volumes of untrusted web content through an external CLI and model gateway. The install path looks same-org/official enough to avoid a malware classification, but the transitive trust chain and prompt-injection exposure make it a medium-risk skill.
Confidence: 89%Severity: 62%
Audit Metadata