deep-research

Warn

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The overall workflow matches a research/report skill, but the footprint is broader than necessary: it auto-installs and registers an external MCP tool with weak provenance evidence, modifies agent configuration, and combines untrusted web ingestion with write/exec capabilities. No confirmed credential theft or covert exfiltration is shown, but the supply-chain and indirect prompt-injection risks are material.

Confidence: 88%Severity: 76%
AnomalyLOW
reports-browser/index.html

This module is primarily a report viewer/exporter, but it contains a high-impact client-side HTML injection sink: PB.innerHTML = marked.parse(m), where m comes from a global report content object RD[k] (origin not shown). If RD content is not guaranteed safe or marked allows/does not sanitize raw HTML, the code can enable DOM XSS. Separately, the module dynamically injects essential third-party scripts at runtime without integrity/pinning controls, creating a supply-chain/code integrity risk if those assets can be tampered with. No direct malware behaviors (exfiltration, credential theft, reverse shells) are evident in the provided fragment.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:06 PM
Package URL
pkg:socket/skills-sh/mxyhi%2Fok-skills%2Fdeep-research%2F@61efb78a1ea7ec8c7dced07bf8e7f8c888cb54cbf78d16be63ca18d4e5705773
Security Audit — socket — deep-research