deep-dive

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and core capabilities are mostly aligned for deep research, and there are no suspicious installers, credentials, or exfiltration endpoints. However, it combines heavy ingestion of untrusted web content with parallel agents and an unnecessary Bash permission, creating a material indirect prompt-injection and over-permission risk for an AI agent skill.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Mar 24, 2026, 02:27 AM
Package URL
pkg:socket/skills-sh/buddyh%2Fagent-skills%2Fdeep-dive%2F@e7c72e6ef8e5ee5e49fde3f15b4d7258e06ccf0b