research-integration
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core behavior fits a research skill, but its footprint is broad: write-capable subagents can fetch arbitrary external content, install packages, clone repos, and run scripts, and the generated API tester disables TLS verification. There is no clear credential-exfiltration path or deceptive concealment, so this is not malware, but it is a medium-risk skill due to expansive autonomous execution and weak install/runtime trust boundaries.
Confidence: 83%Severity: 58%
Audit Metadata