deepwiki

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the DeepWiki MCP skill appears benign with respect to its stated purpose of reading public GitHub repo documentation and performing Q&A. The primary concern is the transitive dependency on the mcporter skill to execute MCP calls, which introduces a trust chain and potential hidden data flows. No explicit credential handling or write/exfiltration is described, and public-data access aligns with the stated scope. Treat the transitive loading as a medium risk due to potential broadened permissions and data exposure from the loaded skill.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 01:29 PM
Package URL
pkg:socket/skills-sh/anntnzrb%2Fagents%2Fdeepwiki%2F@6a047b424ba2330d5bacf40f1409f21941426da9