Deerflow
Security checks across static analysis, malware telemetry, and agentic risk
Overview
This skill is a lightweight local client for a DeerFlow LangGraph service; its files, required binaries, and environment variables match that purpose and there is no evidence of unrelated credential access or hidden behavior.
This skill appears to be a straightforward DeerFlow client. Before installing or using it: 1) Ensure you point DEERFLOW_URL / DEERFLOW_LANGGRAPH to a DeerFlow instance you control or trust; the skill will send HTTP requests to those endpoints. 2) If you intend to deploy DeerFlow yourself, review the bytedance/deer-flow images and .env usage (they will require model API keys) before running docker compose. 3) Note a minor naming inconsistency in configuration files (SKILL metadata and scripts use DEERFLOW_LANGGRAPH while config.yaml references DEERFLOW_LANGGRAPH_URL) — confirm which env var you set. 4) Do not provide unrelated cloud/secret credentials to this skill; it does not need them. If you need higher assurance, inspect the DeerFlow service images and run the service in isolated infrastructure before connecting this skill.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
