agent-deepweb
Warn
Audited by Socket on Aug 31, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core purpose is coherent, and the referenced CLI appears to come from the named same-org source. The main issue is scope mismatch: the declared `Bash(agent-deepweb *)` permission is broader than the skill’s own recommended allowlist, enabling authenticated writes or administrative verbs if the harness follows the wildcard literally. Plaintext cookiejar support also adds local credential exposure risk. Not confirmed malicious, but medium risk due to delegated authenticated network actions plus overly broad execution scope.
Confidence: 84%Severity: 58%
Audit Metadata