autoresearch

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Security
SecurityMEDIUM
autoresearch.md

No explicit malicious code (e.g., embedded backdoor, credential theft, exfiltration routines, or obfuscated payload) is shown in this fragment. However, the workflow is intrinsically high-risk because it is designed to execute arbitrary user-supplied shell commands (Verify/Guard) and optionally chain into downstream commands while repeatedly mutating git history. If an attacker can influence the command arguments or chain targets, this template could be used for host compromise, sabotage, or data leakage via command side effects and/or metric/log outputs. Treat as a command-execution orchestration mechanism requiring strict allowlisting/sandboxing and least-privilege controls.

Confidence: 60%Severity: 70%
Audit Metadata
Analyzed At
Jul 27, 2026, 03:38 AM
Package URL
pkg:socket/skills-sh/full-stack-skills%2Futility-skills%2Fautoresearch%2F@656d8866470ae1f42dfc2dc7aaf2d6151d83c0f9a60ecae47e3d2ccb17cf3c6c
Security Audit — socket — autoresearch