deep-research-surf
Warn
Audited by Socket on May 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose matches its research capabilities, but it materially increases risk by routing research through a third-party Surf MCP service and by processing large volumes of untrusted external content with parallel subagents. This looks like a coherent research skill, not malware, but it carries medium security risk from third-party data flow and indirect prompt injection exposure.
Confidence: 86%Severity: 63%
Audit Metadata