deepsec

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is purpose-aligned and appears to use the official Vercel DeepSec distribution, so it is not clearly malicious. It is still security-sensitive because it installs mutable dependencies, forwards environment credentials into an external AI-assisted scanner, and reads untrusted repo instructions before running a shell-capable agent. Overall classification: SUSPICIOUS due to medium-high operational risk, mainly from prompt-injection and AI security-tool execution rather than deceptive provenance.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 18, 2026, 08:42 PM
Package URL
pkg:socket/skills-sh/vercel-labs%2Fdev3000%2Fdeepsec%2F@5840ebb7cd2bce1050986934eb24eadc04a94648
Security Audit — socket — deepsec