refresh-research
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's core purpose is coherent for repository research maintenance, but it has elevated operational risk because it pulls external content, delegates to another agent, executes repo-defined hooks, and can autonomously commit and push changes. No clear credential theft or malicious exfiltration is present; the main concern is high-impact automation and transitive trust.
Confidence: 89%Severity: 67%
Audit Metadata