autoresearch

Warn

Audited by Socket on May 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s broad autonomous authority is largely consistent with its stated purpose, but that purpose itself is extremely expansive and includes high-risk shell execution, security testing, repository mutation, and real-world publish/deploy/send actions. There is no clear credential-harvesting or covert exfiltration path, and external endpoints appear mostly official, so this is not confirmed malware; however, the autonomy and action scope are disproportionate enough to warrant high security risk.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
May 29, 2026, 09:45 AM
Package URL
pkg:socket/skills-sh/mxyhi%2Fok-skills%2Fautoresearch%2F@8fcc33b4470e7ecf831f4b7851027bfe0cdf746c
Security Audit — socket — autoresearch