autoresearch
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities broadly match its stated purpose, and there is no clear malware or supply-chain deception. The main risk is operational: it grants an AI agent an open-ended autonomous loop that executes shell commands, edits code, commits changes, and pushes to a remote without repeated user confirmation. That is coherent with the purpose but still high-impact and should be treated as a risky automation skill rather than benign.
Confidence: 89%Severity: 72%
Audit Metadata