research
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent for a research skill, and the requested Exa/Firecrawl credentials are proportionate, but the footprint is broadened by transitive skill installation and by giving bash-capable subagents access to untrusted web content. The main concern is indirect prompt injection and trust in unreviewed sibling skills rather than confirmed malware.
Confidence: 87%Severity: 72%
Audit Metadata