deep-research-main

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent and there is no clear credential theft or malicious exfiltration, but it grants a research agent high autonomy, background subagent execution, and broad ingestion of untrusted web content while retaining file-write capability. The main risk is indirect prompt injection and over-broad tool inheritance, with additional privacy exposure if third-party MCP search services are used.

Confidence: 82%Severity: 63%
Audit Metadata
Analyzed At
Mar 27, 2026, 08:09 PM
Package URL
pkg:socket/skills-sh/fivetaku%2Fdeep-research-kit%2Fdeep-research-main%2F@c2b5484e6d8b4ffdf221d6b6e06b6b5ad1615b5e