research
Warn
Audited by Socket on Jul 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose matches web research, and most endpoints are official APIs, but the skill is unsafe because it hardcodes numerous credentials, points to a local API key file, and expands trust to extra tools/skills. This looks more like poor and risky secret handling than confirmed malware, but the overall security risk is high.
Confidence: 88%Severity: 72%
Audit Metadata