research

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches web research, and most endpoints are official APIs, but the skill is unsafe because it hardcodes numerous credentials, points to a local API key file, and expands trust to extra tools/skills. This looks more like poor and risky secret handling than confirmed malware, but the overall security risk is high.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Jul 15, 2026, 12:56 PM
Package URL
pkg:socket/skills-sh/Lua2147%2Fclaude-toolkit-catalog%2Fresearch%2F@afad9556f772bd52fdaacd6d36ccf0dd5a1fff7cad617da9294f83dcc9581e1f
Security Audit — socket — research