ulw-research

Warn

Audited by Socket on Jul 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's research purpose generally matches its capabilities, but it materially increases agent risk by combining recursive multi-agent orchestration, external-content ingestion, code execution, file writes, and transitive loading of other skills. No clear credential theft or exfiltration is present, so this is not confirmed malware, but it is a high-exposure research skill that should be treated as medium-high security risk.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Jul 19, 2026, 05:24 AM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Foh-my-opencode%2Fulw-research%2F@0132b62a4ff36eba3de53224de11cb9372239ed374eeb97c1a1495e94390eaef
Security Audit — socket — ulw-research