autoresearch

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s autonomous experiment-loop behavior matches its stated purpose, but its footprint relies on a third-party Pi package that Pi documents as having full system access. No clear credential harvesting or exfiltration is shown, so this is not confirmed malware, but it carries elevated supply-chain and autonomous-execution risk relative to a simple benchmarking helper.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 20, 2026, 12:42 PM
Package URL
pkg:socket/skills-sh/companion-inc%2Ffeynman%2Fautoresearch%2F@5da9a4bbe3a27cc90b6829c3d83c4c1a6f45bf9a
Security Audit — socket — autoresearch