ulw-research
Warn
Audited by Socket on Aug 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but its operational footprint is broad. It combines recursive web/repo ingestion, subagent swarms, file writes, and code execution, creating high prompt-injection and moderate transitive-trust risk. Tool provenance appears mostly legitimate, so this is not confirmed malware, but it is a high-risk research automation skill.
Confidence: 87%Severity: 71%
Audit Metadata