deepseek

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent, but it relies on a third-party X-CMD CLI rather than an official DeepSeek client, uses remote-script installation, and asks users to hand their DeepSeek API key to that CLI. This is not confirmed malware, but the install path and credential-forwarding design create medium security risk and weaken data-flow integrity.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:41 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fdeepseek%2F@50ac3ca72dae074cdf43a3631b24d3623dfc45ab