deepvista

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
reference/skill.md

SUSPICIOUS: the documented capabilities fit a workflow-management skill, but the required `deepvista` CLI could not be independently verified and the skill supports transitive installation of marketplace skills into the agent environment without visible integrity controls. No direct credential harvesting or clearly malicious data exfiltration is shown in the excerpt.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Apr 22, 2026, 12:17 PM
Package URL
pkg:socket/skills-sh/deepvista-ai%2Fdeepvista-cli%2Fdeepvista%2F@745cdc012bd62d132815fdae66b3b7eb832328bc