ai-rag-pipeline

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated RAG purpose is coherent, but the skill is overpowered for a guide because it grants wildcard Bash, installs other skills, and processes large volumes of untrusted web content through an external CLI and model gateway. The install path looks same-org/official enough to avoid a malware classification, but the transitive trust chain and prompt-injection exposure make it a medium-risk skill.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fai-rag-pipeline%2F@db5005f55cc5e4608a2f6f4f9f9985d15ebe0f70cdded991e272b9d104a821cc
Security Audit — socket — ai-rag-pipeline