deepsec-vulnerability-scanner

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is broadly aligned with a code-scanning purpose, and its npm-based install plus official provider endpoints look plausible. However, it combines package-supplied instructions, full-shell agent behavior, untrusted code analysis, credential use, and optional source upload to Vercel sandboxes, making the overall footprint high-risk and only safe in tightly controlled environments.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
May 5, 2026, 03:16 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fdeepsec-vulnerability-scanner%2F@0d91c48dcd8d05768ae4b742d094174f2a38f0dc