run-research

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent, but the skill combines broad Bash access, optional raw GitHub curl|shell installers, local secret-file probing, and ingestion of untrusted external content. That mix creates high supply-chain and indirect prompt-injection risk disproportionate to a typical research skill, even without clear evidence of confirmed malicious intent.

Confidence: 86%Severity: 81%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:32 PM
Package URL
pkg:socket/skills-sh/gupsammy%2FClaudest%2Frun-research%2F@de03fa0850d322685bb443cc426ec5738e2d34ab
Security Audit — socket — run-research