embedding-ft

Warn

Audited by Socket on May 17, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
references/job-contract.md

The workflow presents a pragmatic, low-retry design emphasizing determinism and safety but introduces a notable dynamic invocation risk through contentFunction supplied by the payload. Without strict whitelisting and sandboxing of contentFunction, there is a medium-to-high risk of code execution or unintended side effects. Atomicity concerns and shutdown-race handling also warrant explicit transactional boundaries and better visibility. Overall, the design is not malicious but requires stronger input validation, function governance, and robust observability to mitigate data integrity and security risks.

Confidence: 65%Severity: 60%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose is coherent, but the execution model is higher risk than necessary: a mutable npm-delivered CLI receives API credentials, and the optional local CLI override further weakens trust boundaries. Data flow to Supabase is plausible for the stated task, yet install trust and credential forwarding are not well constrained.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 17, 2026, 06:58 AM
Package URL
pkg:socket/skills-sh/tiangong-lca%2Fskills%2Fembedding-ft%2F@13142d1acad9ae59c99fc3613bc98420d9a29903
Security Audit — socket — embedding-ft