checkit
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core research behavior is mostly coherent with the stated purpose, but the skill crosses into disproportionate autonomous action by requiring the agent to persist notes and report only after the fact. Risk is increased by ambiguous-intent execution, reliance on an unverifiable local `video_ingest.py` workflow, local browser-cookie use for gated content, and optional routing through non-official third-party social-content services. Not confirmed malware, but it is a medium/high-risk skill due to autonomy and trust-boundary expansion.
Confidence: 88%Severity: 74%
Audit Metadata