deep-interview

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core interviewing/spec-writing behavior is coherent, but the skill deliberately creates a transitive trust chain into other skills and optionally sends summarized project context to an externally configured MCP tool. No clear malware or credential-harvesting behavior is present, yet the downstream autonomy and external-context flow make the overall security posture medium risk rather than benign.

Confidence: 84%Severity: 59%
Audit Metadata
Analyzed At
May 9, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/yeachan-heo%2Foh-my-claudecode%2Fdeep-interview%2F@18ef3de0df39c1db9e1385072b93b7ae3903c5f1