deepsec-vulnerability-scanner
Warn
Audited by Socket on May 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is broadly aligned with a code-scanning purpose, and its npm-based install plus official provider endpoints look plausible. However, it combines package-supplied instructions, full-shell agent behavior, untrusted code analysis, credential use, and optional source upload to Vercel sandboxes, making the overall footprint high-risk and only safe in tightly controlled environments.
Confidence: 82%Severity: 74%
Audit Metadata