research-integration

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s stated purpose is legitimate and largely aligned with its behavior, but its operational footprint is broad: write-capable subagents may fetch untrusted content, install packages, and execute analysis code, it transitively loads another skill, and its generated API test script explicitly disables TLS verification. This is better classified as suspicious/high-risk research automation rather than malware or a credential harvester, because data is intended to flow to official vendor endpoints and local files, not obvious attacker infrastructure.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
May 20, 2026, 08:44 PM
Package URL
pkg:socket/skills-sh/elastic%2Fintegration-skills%2Fresearch-integration%2F@0364daacc455a10d9c84e56aaba0b12ed4d71387
Security Audit — socket — research-integration