research-to-article

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's article-writing purpose broadly matches its capabilities, but it relies on a third-party local toolkit path backed by curl|bash installation evidence and expands trust through delegated skills and autonomous research agents. No confirmed malicious or credential-stealing behavior is shown, yet the combination of third-party execution dependency, transitive skill trust, and untrusted web-content processing makes the overall risk medium-high.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Mar 23, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/notque%2Fclaude-code-toolkit%2Fresearch-to-article%2F@7aaeadafbc9a979f228a35dc6fc4bb6d8edc7dbc