ai-research-reproduction
Warn
Audited by Socket on May 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated purpose is coherent, and its policies are conservative, but it grants an agent a broad orchestration role over untrusted repositories, including command execution, optional training, file writes, and patching via opaque sub-skills whose provenance and behavior are not shown. No direct credential harvesting, exfiltration endpoint, or malicious installer is evident in the provided text, so this is not malware, but the combination of repo-content ingestion plus delegated execution makes it a medium-risk skill.
Confidence: 84%Severity: 58%
Audit Metadata