ai-partner-chat

Fail

Audited by Socket on May 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The core note-indexing and local vector DB behavior matches the stated purpose, and the visible install path is standard pip-based tooling. However, the skill's defining feature—having the agent generate and execute code after analyzing arbitrary note contents—creates a disproportionate indirect prompt-injection/execution risk for a chat-memory skill, even without clear evidence of exfiltration or credential theft.

Confidence: 83%Severity: 59%
Audit Metadata
Analyzed At
May 4, 2026, 03:15 PM
Package URL
pkg:socket/skills-sh/hhhh124hhhh%2FLangGraph-Partner%2Fai-partner-chat%2F@52ab5ed6c7fb79f05a9cdf008619add5d39c27bb
Security Audit — socket — ai-partner-chat