aris-autonomous-ml-research

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core capabilities broadly match autonomous ML research, but its footprint is expansive for an agent skill: it executes code, clones and modifies repositories, routes sensitive prompts and multiple API keys to model providers, and permits custom proxy/base URLs. The main inconsistency is publisher attribution (ara.so) versus install source (wanshuiyin repo), plus added transitive trust through Oracle MCP. Not confirmed malware, but medium-high security risk due to autonomy, external-content processing with exec/write permissions, and flexible credential/data routing.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
May 16, 2026, 04:24 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fclaude-code-skills%2Faris-autonomous-ml-research%2F@4457fdeb596745167004cee58d206b01bfecae9b
Security Audit — socket — aris-autonomous-ml-research