Deepvista Notes
Security checks across malware telemetry and agentic risk
Overview
The skill's requests, commands, and install match its stated purpose (managing notes via the deepvista CLI), but you should verify the deepvista-cli install source and the referenced deepvista-shared skill (auth) before installing.
This skill is internally consistent: it runs the deepvista CLI to manage notes and asks you to use --content-file for imports. Before installing, do two quick checks: (1) verify the 'uv' installer and the deepvista-cli package come from a trustworthy source (registry URL, GitHub releases, or vendor site) and check any package signatures; (2) open the deepvista-shared SKILL.md to see how authentication and tokens are handled (where credentials are stored or which environment variables/config paths are used). When using the skill, avoid asking it to import or read sensitive local files unless you intentionally want them stored in DeepVista, and be cautious about piping content from untrusted remote URLs.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
