deep-research

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No direct malicious code or obvious exfiltration/backdoor behavior found in this artifact. The primary security concern is architectural: the skill implements an automated cross-skill handoff and spawns parallel Tasks, which expands the trusted computing base. If the runtime and the plugin-improve/Task components are properly sandboxed and conversation/context is sanitized before handoff, the risk is low. Recommended mitigations: (1) enforce and audit runtime invariants (read-only enforcement), (2) sanitize/filter conversation history and context before passing to plugin-improve, (3) restrict plugin-improve and Task tool privileges to the minimum necessary, and (4) log and require explicit interactive confirmation for the handoff event to prevent spoofing. Otherwise, the artifact can be considered benign but with moderate operational risk.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:15 AM
Package URL
pkg:socket/skills-sh/glittercowboy%2Fplugin-freedom-system%2Fdeep-research%2F@71b7ddf60168e1dbaffcc66a41d9344b1e77d0c4