company-research
Audited by Socket on Feb 28, 2026
1 alert found:
SecurityOverall, the skill’s stated purpose (company research using Exa and distilling results) is coherent with its capabilities and execution model. The primary security concerns involve external tool usage ( Exa ) which could expose search terms/results to a third-party service and privacy considerations around collecting public LinkedIn and other public data. No credentials, no code execution, and no data exfiltration mechanisms are evident within the fragment. Given the benign interpretation, the risk is primarily privacy/data-use oriented rather than active malware or supply-chain risk. Recommend monitoring data-handling practices and ensuring compliance with data-use policies, but classify as BENIGN with MEDIUM privacy-risk considerations.