autoresearch
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core purpose is coherent, but it grants an agent a broad autonomous self-modification loop over other skills and can ingest untrusted skill content while continuing to edit files. There is no clear credential theft or exfiltration path, so this is not confirmed malware, but it is a high-risk autonomous optimization skill with moderate prompt-injection exposure and minor CDN supply-chain risk.
Confidence: 91%Severity: 74%
Audit Metadata