agent-deepweb

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and the referenced CLI appears to come from the named same-org source. The main issue is scope mismatch: the declared `Bash(agent-deepweb *)` permission is broader than the skill’s own recommended allowlist, enabling authenticated writes or administrative verbs if the harness follows the wildcard literally. Plaintext cookiejar support also adds local credential exposure risk. Not confirmed malicious, but medium risk due to delegated authenticated network actions plus overly broad execution scope.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Aug 31, 2026, 09:41 PM
Package URL
pkg:socket/skills-sh/shhac%2Fagent-skills%2Fagent-deepweb%2F@2b919945c887517e123d57ed4b0932fb88bed995aa1ca1d7e59fba07b7dfa42a
Security Audit — socket — agent-deepweb