create-skill-autoresearch

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent, but the skill’s footprint is too expansive: it installs or relies on other skills, executes shell-based evaluation loops, sends data to undefined third-party-compatible model endpoints, and processes untrusted external content while retaining write/exec powers. This is not confirmed malware, but it is a high-risk orchestration skill with disproportionate transitive trust and data-flow ambiguity.

Confidence: 86%Severity: 80%
Audit Metadata
Analyzed At
Jul 7, 2026, 01:28 PM
Package URL
pkg:socket/skills-sh/a-tokyo%2Fagent-skills%2Fcreate-skill-autoresearch%2F@fadf04ea733a6bf55512eb0922b7494c1e172f8f55c3529d50bf0c9bfa4654d4
Security Audit — socket — create-skill-autoresearch