deepread-byok

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent with its stated BYOK purpose and uses same-org DeepRead infrastructure, but it requires users to hand third-party provider keys to DeepRead and keeps all document processing routed through DeepRead. That is disclosed rather than hidden, so this is not confirmed malware, but it is a meaningful credential-forwarding and data-handling trust expansion.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 5, 2026, 03:03 AM
Package URL
pkg:socket/skills-sh/deepread-tech%2Fskills%2Fdeepread-byok%2F@c7142f8f569717a73a23167abfdea1c5163d7170