deep-dive

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent as an orchestrator for investigation and spec generation, and it includes a meaningful guard against trace-based prompt injection. The main risk is transitive: it reads untrusted project content, reinjects summaries into prompts, persists shared state, and then hands execution to other skills. No direct credential theft, exfiltration endpoint, installer abuse, or obvious malicious behavior is present, but the combination of prompt-processing plus downstream autonomous handoff makes it higher risk than a simple documentation or single-purpose planning skill.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Mar 24, 2026, 07:43 AM
Package URL
pkg:socket/skills-sh/sehoon787%2Fmy-claude%2Fdeep-dive%2F@a0ca740fca345e96400d3c8cbb25d251da66d415
Security Audit — socket — deep-dive