ulw-research

Warn

Audited by Socket on Aug 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its operational footprint is broad. It combines recursive web/repo ingestion, subagent swarms, file writes, and code execution, creating high prompt-injection and moderate transitive-trust risk. Tool provenance appears mostly legitimate, so this is not confirmed malware, but it is a high-risk research automation skill.

Confidence: 87%Severity: 71%
Audit Metadata
Analyzed At
Aug 9, 2026, 12:45 PM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Flazycodex%2Fulw-research%2F@b121c3df56b5c5541935e1411cd9b52beac11514cab7eaec871c7e0d351196f6
Security Audit — socket — ulw-research