autocontext

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a context-management skill, but the actual trust boundary is unacceptable: it requires an unverifiable external `autocontext` CLI, forwards Pinecone credentials to it, and sends data to an unspecified API instance. With missing provenance for the binary and undocumented network endpoints, the skill's footprint is not sufficiently trustworthy for its claimed publisher.

Confidence: 89%Severity: 86%
Audit Metadata
Analyzed At
Apr 17, 2026, 03:07 PM
Package URL
pkg:socket/skills-sh/pinecone-io%2Fpckle-cli%2Fautocontext%2F@814d8de0229b6c6ae34fb73c89393b214a62c4f2
Security Audit — socket — autocontext