research

Warn

Audited by Socket on May 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core file-reading and report-writing behavior fits a research skill, but the footprint expands beyond that through undeclared backend/task capabilities and an optional `ao` CLI whose documented provenance/commands are inconsistent with the evidence provided. The largest practical risk is indirect prompt injection from untrusted codebase content combined with Bash and Write access, plus moderate supply-chain uncertainty around `ao`.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 24, 2026, 09:34 PM
Package URL
pkg:socket/skills-sh/boshu2%2Fagentops%2Fresearch%2F@3cae7ae80946ac12a7ce0ec10baeb1041884b014
Security Audit — socket — research