autoresearch

Fail

Audited by Snyk on Jun 20, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The package intentionally gives an external LLM process autonomous write/commit/execute privileges (via the claude CLI + --permission-mode bypassPermissions and by instructing the agent to git-commit, run fitness commands, and edit files), which creates a high-risk remote-code-execution and data-exfiltration vector that could be abused to install backdoors, leak secrets, or modify the supply chain.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 20, 2026, 06:10 PM
Issues
1
Security Audit — snyk — autoresearch