autoresearch-agent
Warn
Audited by Socket on Apr 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core behavior matches its stated purpose, but its footprint is high-risk by design because it enables indefinite autonomous file modification, git state changes, and execution of arbitrary evaluation commands. Install trust is mixed: same-author GitHub sourcing is coherent, yet distribution is mutable/manual and the ClawHub package reference was not fully verified. No strong evidence of credential theft, exfiltration, or hidden behavior was found.
Confidence: 85%Severity: 62%
Audit Metadata