pipes-sdk

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall behavior matches blockchain indexer development, but its most important capability is delegated to an unpinned third-party npm package whose publisher identity does not clearly align with the claimed skill author. That mismatch raises supply-chain trust concerns, though there is no strong evidence of credential theft, hidden exfiltration, or behavior fundamentally incompatible with the stated purpose.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 9, 2026, 02:33 PM
Package URL
pkg:socket/skills-sh/subsquid-labs%2Fagent-skills%2Fpipes-sdk%2F@9538d79080f66c4d58e8a185650bc0c91097477a
Security Audit — socket — pipes-sdk