deepvista-recipe-export-knowledge-as-skills

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The recipe’s core behavior is coherent and mostly local, but trust is weakened by unverified DeepVista CLI provenance, an unnecessary `uv` requirement, and explicit transitive skill loading/install behavior. No direct credential theft or exfiltration is shown, so this is better classified as medium-risk supply-chain and trust-chain exposure rather than malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 7, 2026, 05:25 AM
Package URL
pkg:socket/skills-sh/deepvista-ai%2Fdeepvista-cli%2Fdeepvista-recipe-export-knowledge-as-skills%2F@de29ae46bc95f3f00c8d0b5b6eacd09146f6d0b6