deepagents-guide

Fail

Audited by Socket on Feb 24, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This fragment is a usage guide and configuration examples for an agent framework. It contains no direct malicious code, no download-execute patterns, no hardcoded secrets, and no obfuscated payloads. The realistic security risks are feature-level: tools that perform destructive or external actions (deleteFile, sendEmail), persistent storage that may hold sensitive data, and database integrations that rely on environment-stored credentials. These are expected capabilities for such a framework but require runtime access controls, careful tool implementation review, and secure handling of credentials. I find no evidence of deliberate malware in the provided text.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 24, 2026, 10:18 PM
Package URL
pkg:socket/skills-sh/ma-pony%2Fdeepspider%2Fdeepagents-guide%2F@5badb14fa97e510cbfff0d948194b45c6e6b9210