auto-research
Warn
Audited by Socket on May 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core purpose is coherent, and it does not show obvious credential theft or deceptive install behavior. However, it combines autonomous operation, external web research, sub-agents, local command execution, and file rewriting of agent instructions, creating medium-to-high risk from indirect prompt injection and unintended local changes.
Confidence: 85%Severity: 67%
Audit Metadata