deep-research-academic
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core purpose is legitimate and its install path appears same-org/official, but it grants a research agent high autonomy over untrusted web content while preserving file-write, script-execution, and subagent capabilities. The main risk is prompt-injection and transitive-action exposure rather than malware or credential theft.
Confidence: 87%Severity: 67%
Audit Metadata