ulw-research
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose matches research orchestration, but its actual footprint is high-risk: recursive ingestion of untrusted external content, autonomous task fan-out, transitive skill loading, repo checkout, and code execution for verification. Install sources mentioned are mostly official and proportionate, so this is not confirmed malware, but the combined agent-action surface makes the skill dangerous to run without strong containment and approval controls.
Confidence: 90%Severity: 74%
Audit Metadata