autoresearch
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is coherent for a meta-skill, but its footprint is broad. The main risk is not malware-like behavior; it is that the skill combines web ingestion, file rewriting, and autonomous git/PR actions, creating indirect prompt-injection and repository-impact risk. External install trust looks mostly benign, but secret-bearing API calls via a local wrapper reduce data-flow clarity.
Confidence: 87%Severity: 69%
Audit Metadata