add-sanity-chatbot
Fail
Audited by Socket on Mar 4, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The code fragment is largely coherent with its stated purpose: it documents a legitimate integration pattern for adding an AI chatbot to a Next.js + Sanity project, using MCP and Anthropic, with explicit credential placeholders and environment configuration. There are no evident malicious behaviors, no suspicious external domains, and the data flows align with expected API interactions. While the setup involves sensitive tokens and external API calls, these are intrinsic to the described functionality and not inherently malicious. Overall, the skill appears benign but high-risk in terms of credential exposure risk and dependency trust (depending on the provenance of the SDKs).
Confidence: 95%Severity: 90%
Audit Metadata