create-skill-autoresearch
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, but the skill’s footprint is too expansive: it installs or relies on other skills, executes shell-based evaluation loops, sends data to undefined third-party-compatible model endpoints, and processes untrusted external content while retaining write/exec powers. This is not confirmed malware, but it is a high-risk orchestration skill with disproportionate transitive trust and data-flow ambiguity.
Confidence: 86%Severity: 80%
Audit Metadata