tiangong-kb-ingest

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and stated boundaries are mostly coherent, and it avoids disproportionate credential requests, but it relies on a local Tiangong CLI/wrapper whose official provenance was not verified from the provided evidence. Main risk is supply-chain and trust in an opaque external tool handling local document uploads, not clear malicious behavior.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 8, 2026, 06:30 PM
Package URL
pkg:socket/skills-sh/tiangong-ai%2Fskills%2Ftiangong-kb-ingest%2F@5a23deba4017e844f5f524e145b8c03f968d8e1c