deer-sense

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for an accessibility-audit skill, and data flows stay mostly local with no credential harvesting. However, the skill instructs the agent to execute a local `tools/glimpse` CLI whose provenance cannot be independently verified from the provided evidence, and its `npx axe` guidance is ambiguous/outdated versus the current official package. Main concern is supply-chain/install trust rather than confirmed malicious intent.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:16 AM
Package URL
pkg:socket/skills-sh/autumnsgrove%2Fgroveengine%2Fdeer-sense%2F@372fa493a04e100705f31504424f7e87e34d4b57