deepcode-cli
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly consistent with a terminal AI assistant, and its primary API endpoints are official provider URLs, but it expands trust significantly through runtime-installed MCP packages, credential forwarding, and optional arbitrary local scripts. The biggest concern is not overt malware but moderate supply-chain and data-handling risk combined with inconsistent publisher identity.
Confidence: 86%Severity: 58%
Audit Metadata