deep-research
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The core research workflow is mostly coherent, but the skill overreaches by making public blog publication a mandatory completion gate and by encouraging autonomous external actions without explicit per-report approval. Third-party search-cli usage is somewhat verifiable and not by itself malicious, but it adds medium supply-chain and credential-forwarding risk. Overall this looks like a legitimate research skill with disproportionate automation and publication behavior rather than confirmed malware.
Confidence: 88%Severity: 74%
Audit Metadata