deep-research

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose matches the capability, and the prompt goes to Google’s official Gemini service, but the skill relies on a locally run automation script plus an MQTT-controlled browser proxy extension whose provenance is not established in the evidence. Risk is moderate rather than malicious: acceptable purpose alignment, but unresolved install-trust and prompt-injection exposure keep it from benign.

Confidence: 79%Severity: 56%
Audit Metadata
Analyzed At
Mar 15, 2026, 12:46 AM
Package URL
pkg:socket/skills-sh/soul-brews-studio%2Foracle-skills-cli%2Fdeep-research%2F@edc3afcc68e5a92c4d0e34e9efdf82bea1b310e9