sandbase

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a unified AI/API gateway, but it centralizes a very broad set of external capabilities and data flows through SandBase rather than official per-provider APIs. No clear malware indicators or malicious exfiltration instructions are present, but the intermediary routing and underdocumented `sandbase connect` trust path make it a medium-risk skill.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
Aug 19, 2026, 03:38 AM
Package URL
pkg:socket/skills-sh/sandbaseai%2Fcli%2Fsandbase%2F@f9f60e5b25fd1bc06e1a370e3912b1c57db07aa52f89f0c42ded4263de15067c
Security Audit — socket — sandbase