kagi-enrich
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose, credential scope, and API data flow are mostly consistent with a Kagi search integration, but its main risk is the install model: downloading and executing a prebuilt binary from a personal GitHub repo, then supplying an API key to that binary. That makes it a supply-chain and credential-forwarding concern despite otherwise coherent functionality.
Confidence: 88%Severity: 82%
Audit Metadata