universal-research-orchestrator

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, but it gives an agent high-autonomy web research behavior over arbitrary untrusted content and includes local archiving/writing, creating meaningful indirect prompt-injection and security-research risk. No clear credential theft, malicious install path, or fixed exfiltration endpoint is present.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 2, 2026, 04:36 PM
Package URL
pkg:socket/skills-sh/Lu1sDV%2Fskillsmd%2Funiversal-research-orchestrator%2F@817e5b86c8f803f3df074d95faa77fec8c895eab