deep-research

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Best available assessment treats the Deep Research skill fragment as a well-structured, legitimate orchestration framework with legitimate research intent. However, its reliance on a broad, transitive, externally sourced toolchain and lack of explicit safeguards around tool provenance, credential handling, and data minimization create a notable supply-chain and runtime risk. A strengthened design with explicit SBOMs, origin verification, sandboxed execution, and credential management would elevate trust and reduce risk.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 03:29 PM
Package URL
pkg:socket/skills-sh/mikeng-io%2Fagent-skills%2Fdeep-research%2F@8008d65e979cc1779b078053c71e963cb08ca610