agent-reach
Warn
Audited by Socket on Sep 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s research-routing purpose broadly matches its capabilities, but it centralizes browsing through a custom Docker router, relies on nonstandard install/update paths, and references unpinned GitHub-based tool installation. Data flows are mostly proportionate to a read-only research skill, yet supply-chain trust is too weak to classify as benign.
Confidence: 90%Severity: 72%
Audit Metadata