ml-autoresearch

Warn

Audited by Socket on Jun 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core ML loop is coherent with its stated purpose, but it grants broad autonomous edit/execute behavior, runs indefinitely without further approval, and can install/delegate to an unreviewed sibling skill that may access external search APIs. The main concern is not obvious malware in this file, but disproportionate autonomy, transitive trust, and optional external-content-driven code changes.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Jun 23, 2026, 04:43 PM
Package URL
pkg:socket/skills-sh/gaasher%2Fagent-loop-skills%2Fml-autoresearch%2F@c6c7a5ab6a7d5fd285f50a82ed6700f9d010c861f2227cb3071dbb7159614e89
Security Audit — socket — ml-autoresearch