parallel-deep-research

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill correctly documents how to run deep research jobs with parallel-cli, but it follows high-risk supply-chain patterns: it recommends curl | bash install of a remote script without integrity verification, requests environment-stored API keys, and delegates capabilities to a third-party CLI. Those patterns meaningfully increase the chance of compromise if the upstream installer or service is malicious or becomes compromised. There is no direct evidence in this YAML of embedded malware or backdoors, but the instructions create a transitive trust and execution risk that should be mitigated. Recommendations: avoid running curl|bash without auditing the script and verifying signatures/checksums; prefer installing from verified package distributions or pinned releases; use short-lived, least-privilege credentials and isolate installation (container/VM) until the binary is audited; restrict tool permissions rather than using wildcards.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Mar 2, 2026, 11:28 PM
Package URL
pkg:socket/skills-sh/parallel-web%2Fagent-skills%2Fparallel-deep-research%2F@a9058e9af677ca880689910432cd163b5c194660