autoresearch-skill

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/dashboard-template.html

No explicit malicious payload logic is present in the visible renderer code. The dominant security concern is that the module dynamically injects and executes a generated script (./results.js?ts=...), creating an arbitrary JavaScript execution risk if that artifact (or its hosting/generation pipeline) is tampered with. Additionally, the code relies on extensive innerHTML rendering and custom markdown/table rendering; while code fences are escaped, full XSS safety cannot be guaranteed from the truncated snippet, so DOM-based XSS remains a secondary risk tied to the unseen markdown helper implementations.

Confidence: 62%Severity: 66%
Audit Metadata
Analyzed At
Aug 4, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/alpoxdev%2Fhypercore-skills%2Fautoresearch-skill%2F@912579956e9dc70066ed00f8b437778ef8eee1987cb99952dd9b62d755baa6ef
Security Audit — socket — autoresearch-skill