NYC

deep-research

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The deep-research Skill itself is functionally benign and aligned with its documented purpose (web search + structured report generation). There are no direct indicators of embedded malware, obfuscation, or hardcoded credentials in this file. However, the declared allowed-tool permissions (Bash, Read/Write/Edit) and example of executing a local research script enlarge the attack surface: malicious or compromised repository scripts or third-party MCP providers could exfiltrate data or execute arbitrary commands. Operationally, treat this as a moderate supply-chain risk: audit any local scripts (e.g., scripts/research.py) before enabling Bash execution and avoid routing sensitive queries through untrusted MCP providers.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:42 PM
Package URL
pkg:socket/skills-sh/z0gsh1u%2Foh-my-writing-skill%2Fdeep-research%2F@dd8e96f53ef8d4462afc0553853f0e43a3b4f67c