Deep Search

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/deep_search.py

Not outright malicious, but contains clear security and privacy issues: hardcoded Langfuse keys and default host, telemetry that exfiltrates user queries and model outputs when tracing is available, broad exception swallowing, and a syntax bug at the file end. Recommended actions before use: remove embedded secrets, require explicit opt-in for telemetry, avoid defaulting tracing host/keys in source, log less sensitive output or redact queries in logs, fix the syntax error, and surface errors rather than silently swallowing them. Treat as privacy-sensitive code and audit any Langfuse credentials for unauthorized use.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 07:43 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fdeep-search%2F@a8c2c9000931a5b40dabf6db56f1196508cce9c1