autoresearch

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s core purpose matches its capabilities, but it normalizes high-autonomy operation with --allow-all, unattended overnight experimentation, and automatic repository changes. The Copilot CLI provenance appears official, so supply-chain concern is limited; the main risk is autonomous modification of prompt/code assets with broad local execution and write access.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:55 PM
Package URL
pkg:socket/skills-sh/elihuvillaraus%2Fskills%2Fautoresearch%2F@e4122146fd41ffe35c923b1ceca5802ffb74ed96
Security Audit — socket — autoresearch