deep-research

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose fits browser automation for Gemini research, and the destination domain is official Google Gemini. However, the skill depends on an unverified browser proxy extension and an unseen local script, creating a significant trust gap. No direct credential theft or clearly malicious data exfiltration is visible, but the unverifiable execution chain makes the skill medium-high risk.

Confidence: 81%Severity: 74%
Audit Metadata
Analyzed At
Apr 21, 2026, 07:18 AM
Package URL
pkg:socket/skills-sh/Soul-Brews-Studio%2Foracle-skills-cli%2Fdeep-research%2F@06781198b85abbca907e27f5dd0bd0aa57fcd20d