deep-research

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/install.sh

No direct indicators of malicious payloads (no credential theft, exfiltration, reverse shell, persistence, or obfuscated execution) are present in this Bash installer fragment. The main risk is supply-chain: it fetches and installs third-party code/dependencies from external GitHub URLs and PyPI using npx/pip/git without pinning to immutable versions and without integrity/signature verification. Treat this as a potentially risky installer and review/pin upstream revisions and dependency versions/hashes before use.

Confidence: 78%Severity: 60%
Audit Metadata
Analyzed At
Jul 28, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Fdeep-research%2F@c44d87ffc27ed1b407eb050ccfc56254fe9745dd0131f4e3cb81f9787415bde9
Security Audit — socket — deep-research