academic-research-skills-codex

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent, and its optional Anthropic credential is proportionate, but the install provenance is not cleanly aligned with the claimed publisher. The main concern is supply-chain trust: mutable GitHub installation through a local installer script, with unclear ara.so-to-Imbad0202 ownership verification. No clear evidence of credential theft, hidden exfiltration, or malicious payloads is present in the provided text.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
May 17, 2026, 09:16 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fcodex-skills%2Facademic-research-skills-codex%2F@eb51ff4b9de7e627e4e9330928a321a3c007dfd2