company-research

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Benign overall. The manifest describes a controlled, isolation-friendly company-research skill that relies on an official search API (Exa) and internal task agents to distill results. There are no evident credential reads, no download/execute patterns, and no direct data exfiltration. Privacy considerations exist around collecting and aggregating public LinkedIn and other public data; ensure user-consent and data-retention policies are followed. Overall, the footprint is coherent with the stated purpose, with moderate risk mainly around data privacy handling rather than supply-chain or execution risk.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 09:56 AM
Package URL
pkg:socket/skills-sh/liangdabiao%2Fexa-research-mcp-skill%2Fcompany-research%2F@0d2385cc0071b1219cc9316cf492911f67046a16