opensearch-skills

Warn

Audited by Socket on May 6, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
observability/trace-analytics/SKILL.md

SUSPICIOUS: The skill’s purpose broadly matches trace analytics, but it expands trust to remotely fetched MCP packages, forwards OpenSearch/AWS credentials into those tools, and documents disabling TLS verification. The overall footprint is plausible for the task but carries meaningful supply-chain and credential-handling risk rather than clear malicious intent.

Confidence: 83%Severity: 64%
AnomalyLOW
SKILL.md

SUSPICIOUS. The core OpenSearch functionality is coherent and the publisher appears legitimate, but the skill expands trust by instructing the agent to install additional skills, run `uvx` MCP servers at `@latest`, and modify local MCP config files. Risk is driven more by transitive installation and external tool execution than by any clear malicious data exfiltration.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
May 6, 2026, 10:09 AM
Package URL
pkg:socket/skills-sh/opensearch-project%2Fopensearch-agent-skills%2Fopensearch-skills%2F@3ab13db679f83933293e1445ac2d9f09080aea82