autoresearch
Warn
Audited by Socket on May 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s broad autonomous authority is largely consistent with its stated purpose, but that purpose itself is extremely expansive and includes high-risk shell execution, security testing, repository mutation, and real-world publish/deploy/send actions. There is no clear credential-harvesting or covert exfiltration path, and external endpoints appear mostly official, so this is not confirmed malware; however, the autonomy and action scope are disproportionate enough to warrant high security risk.
Confidence: 90%Severity: 82%
Audit Metadata