research
Warn
Audited by Socket on May 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core file-reading and report-writing behavior fits a research skill, but the footprint expands beyond that through undeclared backend/task capabilities and an optional `ao` CLI whose documented provenance/commands are inconsistent with the evidence provided. The largest practical risk is indirect prompt injection from untrusted codebase content combined with Bash and Write access, plus moderate supply-chain uncertainty around `ao`.
Confidence: 100%Severity: 60%
Audit Metadata