deep-research

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches research orchestration, but its footprint is broad: autonomous background subagents, browser automation, Bash execution, and arbitrary web-content ingestion. The biggest issue is indirect prompt-injection risk from combining untrusted external content with tools that can execute commands and write files; secondary concern is the unpinned npx chromux fallback. No clear credential harvesting or exfiltration behavior is shown, so this is not confirmed malware.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 20, 2026, 01:32 PM
Package URL
pkg:socket/skills-sh/team-attention%2Fhoyeon%2Fdeep-research%2F@f30eb70f94e81331c6ab932805a85eef216a9e60
Security Audit — socket — deep-research