autoresearch

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core purpose matches prompt optimization, and there is no clear credential theft or exfiltration path. However, its explicit autonomous loop ('NEVER STOP'), ability to read arbitrary skill/reference content and then modify files, and browser-opening behavior make it a high-risk agent capability. The CDN dependency is official and low risk, but the autonomy and indirect prompt-injection exposure push the overall classification above benign.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Apr 23, 2026, 09:49 AM
Package URL
pkg:socket/skills-sh/marcoax%2Fskills%2Fautoresearch%2F@2ee5cdec9a40ac5f2deb9e35851298d83066ae51
Security Audit — socket — autoresearch