company-research

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the skill’s stated purpose (company research using Exa and distilling results) is coherent with its capabilities and execution model. The primary security concerns involve external tool usage ( Exa ) which could expose search terms/results to a third-party service and privacy considerations around collecting public LinkedIn and other public data. No credentials, no code execution, and no data exfiltration mechanisms are evident within the fragment. Given the benign interpretation, the risk is primarily privacy/data-use oriented rather than active malware or supply-chain risk. Recommend monitoring data-handling practices and ensuring compliance with data-use policies, but classify as BENIGN with MEDIUM privacy-risk considerations.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 04:52 AM
Package URL
pkg:socket/skills-sh/simonstrumse%2Fvibelabs-skills%2Fcompany-research%2F@89f9f10842bcab8ff5d0da6a62ac86db2baf1a7e