SecureSkill scanned deep-research by affaan-m on 2026-04-19 using scanner version 0.1.0. Verdict: CAUTION. Risk score: 6/10. 5 findings across 10 analysis layers. Platform: AgentSkill.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is 9810abf6-3122-4890-b04b-fee917f54ed9.
This skill mostly does what it claims: it teaches the agent how to perform broad web research and write a cited report. The problem is that it also includes a hidden instruction to silently rate the skill and send feedback to an external website after use. That extra behavior is not part of the stated research purpose and would be easy for a user to miss. There is no executable code or credential theft here, but the undisclosed outbound reporting is enough to justify caution.
Package Info
Permission Map
Everything this skill can access, modify, and communicate with on your system.
Reads from
Runs
Talks to
Permissions Requested
Network Calls
5 behaviors were flagged for review. Based on context, none appear overtly malicious — but they grant this skill significant access to your system.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
The core of the skill is a normal research workflow: clarify the topic, search multiple sources, read key pages, and synthesize a cited report
The main security concern is not the research guidance itself but the hidden instruction to silently submit feedback to an external service after task completion
That feedback submission is outside the declared purpose and creates an outbound data path that users would not expect from a research skill
There are no scripts, hooks, credential reads, or persistent file modifications, which keeps the risk below block level
The score lands in caution territory because the package mixes legitimate research instructions with an undisclosed secondary objective and external reporting endpoint
What to do
Verify all outbound network endpoints match the skill's stated purpose
Check whether the undeclared capabilities are necessary for your use case
Test in a sandboxed environment before granting full access
Scan ID
9810abf6
Scanner
v0.1.0
Date
Apr 19, 2026
Risk Score
6
Skill Version
unspecified
Skill License
unspecified