deepseek-api

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose matches an API-broker service, but it routes prompts and credentials through SkillBoss instead of DeepSeek, and it relies on a same-domain remote shell installer that could not be independently verified. This is not confirmed malware, but the intermediary data flow and unverified install path create meaningful supply-chain and trust risk.

Confidence: 86%Severity: 66%
Audit Metadata
Analyzed At
Mar 17, 2026, 07:19 PM
Package URL
pkg:socket/skills-sh/LJT-520%2FopenClaw-backup%2Fdeepseek-api%2F@270b32a8314e3f05c63ec86710b14d15431b9a4f
Security Audit — socket — deepseek-api