deepcode-cli

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly consistent with a terminal AI assistant, and its primary API endpoints are official provider URLs, but it expands trust significantly through runtime-installed MCP packages, credential forwarding, and optional arbitrary local scripts. The biggest concern is not overt malware but moderate supply-chain and data-handling risk combined with inconsistent publisher identity.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 16, 2026, 10:22 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdevtools-skills%2Fdeepcode-cli%2F@45170add01ea680eab9d9f3dbad6ac517e971cba