research

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a research skill, and the requested Exa/Firecrawl credentials are proportionate, but the footprint is broadened by transitive skill installation and by giving bash-capable subagents access to untrusted web content. The main concern is indirect prompt injection and trust in unreviewed sibling skills rather than confirmed malware.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
May 15, 2026, 09:33 PM
Package URL
pkg:socket/skills-sh/FasalZein%2Fautonomous-research-skill%2Fresearch%2F@72782d9392f356cc646728fd593579d3f54b4f16
Security Audit — socket — research