deepvista-recipe-research-to-vistabook
Warn
Audited by Socket on Mar 31, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The recipe’s read-then-run behavior matches its stated purpose, and it even asks for user confirmation before the write step. The main concerns are transitive skill loading and reliance on an unverified `deepvista` CLI/provenance path, which make trust and data-boundary assumptions unclear even though no explicit credential theft or malicious exfiltration is shown.
Confidence: 81%Severity: 56%
Audit Metadata