deep-dive

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent as an orchestrator for investigation and spec generation, and it includes a meaningful guard against trace-based prompt injection. The main risk is transitive: it reads untrusted project content, reinjects summaries into prompts, persists shared state, and then hands execution to other skills. No direct credential theft, exfiltration endpoint, installer abuse, or obvious malicious behavior is present, but the combination of prompt-processing plus downstream autonomous handoff makes it higher risk than a simple documentation or single-purpose planning skill.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/yeachan-heo%2Foh-my-claudecode%2Fdeep-dive%2F@f6533e2167f91b288fafc0594bc99cbd257e7fe0