researching-codebases

Fail

Audited by Socket on Feb 19, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
agents/web-searcher.md

This manifest configures a capable web-research subagent that, while designed for legitimate information retrieval and synthesis, grants broad privileges that create straightforward and significant data-exfiltration paths (local file enumeration/reads combined with unrestricted outbound network access and third-party model calls). No explicit malicious code is present in the fragment; the primary risk is abuse or accidental leakage due to overly permissive defaults. Before deploying in sensitive environments, enforce least-privilege access, network allowlists, prompt/data sanitization, and auditing.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 19, 2026, 11:28 PM
Package URL
pkg:socket/skills-sh/cachemoney%2Fagent-toolkit%2Fresearching-codebases%2F@36818ca7a6d184bcc8b95673b3d26d4095eda29c