external-research

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, and the referenced upstream service (Context7/Upstash) is legitimate, but the skill routes through an undocumented custom '/external-scout' command and has the agent ingest untrusted external content that can shape subsequent code changes. Main risk is indirect prompt injection plus partial install/execution trust ambiguity, not confirmed malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 14, 2026, 07:09 PM
Package URL
pkg:socket/skills-sh/darrenhinde%2Fopencode-agents%2Fexternal-research%2F@6ae057a30e9dfeb8b9d467d3836f5df4b7c9fd71