autoresearch
Warn
Audited by Socket on May 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s research-orchestration purpose broadly matches its file and experiment management behavior, but its footprint is high-risk because it mandates indefinite autonomous operation, transitive use of other skills, ingestion of untrusted external content with write/exec capability, and unsolicited outbound messaging to Telegram/WhatsApp/Slack. Install sources are mostly normal developer tooling and do not by themselves suggest malware, but the autonomy and data-flow design are disproportionate for a general skill.
Confidence: 89%Severity: 82%
Audit Metadata