deep-research

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core research workflow is mostly coherent, but the skill overreaches by making public blog publication a mandatory completion gate and by encouraging autonomous external actions without explicit per-report approval. Third-party search-cli usage is somewhat verifiable and not by itself malicious, but it adds medium supply-chain and credential-forwarding risk. Overall this looks like a legitimate research skill with disproportionate automation and publication behavior rather than confirmed malware.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Sep 7, 2026, 09:40 PM
Package URL
pkg:socket/skills-sh/lovstudio%2Fskills%2Fdeep-research%2F@1bba6c7002eae837ea3c0be1e9878302d2f17fb9d624d04072a33081cfa7dd53
Security Audit — socket — deep-research