autoresearch
Warn
Audited by Socket on May 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s autonomous experiment-loop behavior matches its stated purpose, but its footprint relies on a third-party Pi package that Pi documents as having full system access. No clear credential harvesting or exfiltration is shown, so this is not confirmed malware, but it carries elevated supply-chain and autonomous-execution risk relative to a simple benchmarking helper.
Confidence: 84%Severity: 72%
Audit Metadata