res-deep

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent for a research skill, and the uv installer appears to be an official same-org distribution path rather than a random payload. However, the skill materially increases risk by combining broad ingestion of untrusted web content with shell/tool execution, mandatory credential probing via the macOS keychain, and optional stealth scraping/Cloudflare-bypass tooling. This looks more like a high-risk agentic research workflow than malware, but its capability footprint is broader and riskier than a typical benign documentation-style research skill.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Mar 14, 2026, 09:36 PM
Package URL
pkg:socket/skills-sh/MOlechowski%2Fagent-skills%2Fres-deep%2F@4d97843ff04db7fcdcf694ad6cf78fd63dab011e