deepsource

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (retrieve code review results, vulnerabilities, and analysis status via DeepSource CLI) aligns with the described commands and authentication flow. Data flows are mainly from DeepSource to the agent, with standard authentication. There are no evident use of unverifiable binaries, suspicious exfiltration paths, or overly broad permissions. The main security considerations are credential handling (token storage and revocation) and ensuring the CLI’s authentication state remains scoped and revocable. Overall, the footprint is coherent and proportionate to its purpose, with moderate but manageable security considerations related to local credential storage.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:49 PM
Package URL
pkg:socket/skills-sh/DeepSourceCorp%2Fskills%2Fdeepsource%2F@87b43eee34db7a12db5469fddebfb277f107270f