kagi-summarizer

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and data flow are mostly coherent and it uses Kagi's official API, but the installation model introduces notable trust risk. It downloads and executes a mutable prebuilt binary from a personal GitHub publisher rather than Kagi, and that code receives the user's KAGI_API_KEY. Public source and release history reduce the likelihood of outright malware, but the third-party supply-chain and credential-forwarding footprint is broader than ideal for a simple summarizer wrapper.

Confidence: 86%Severity: 66%
Audit Metadata
Analyzed At
Mar 27, 2026, 08:25 PM
Package URL
pkg:socket/skills-sh/joelazar%2Fkagi-skills%2Fkagi-summarizer%2F@e86a67f951a6a850398b6407102517ef25f1b393