autoresearch
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
SecuritySecurityautoresearch.md
MEDIUMSecurityMEDIUM
autoresearch.md
No explicit malicious code (e.g., embedded backdoor, credential theft, exfiltration routines, or obfuscated payload) is shown in this fragment. However, the workflow is intrinsically high-risk because it is designed to execute arbitrary user-supplied shell commands (Verify/Guard) and optionally chain into downstream commands while repeatedly mutating git history. If an attacker can influence the command arguments or chain targets, this template could be used for host compromise, sabotage, or data leakage via command side effects and/or metric/log outputs. Treat as a command-execution orchestration mechanism requiring strict allowlisting/sandboxing and least-privilege controls.
Confidence: 60%Severity: 70%
Audit Metadata