research-note

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s core note-writing behavior is coherent, but it also instructs the agent to delete source material and commit to git automatically without user confirmation. There is no sign of credential theft, malware, or suspicious installation, but the autonomous destructive and version-control actions make the skill high-risk for unintended repository changes.

Confidence: 91%Severity: 72%
Audit Metadata
Analyzed At
Apr 5, 2026, 12:43 AM
Package URL
pkg:socket/skills-sh/gkwa%2Fvolcanicviper%2Fresearch-note%2F@097add9d59bf34e7149a99d0c01f4093b65c254b
Security Audit — socket — research-note