octopus-research
Warn
Audited by Socket on May 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated research purpose is plausible, but the skill forces all work through an opaque local executable in the user's home directory and then surfaces files/logs it creates. That unverifiable execution dependency is disproportionate to a markdown skill and prevents verification of where prompts, fetched content, or provider data actually flow.
Confidence: 83%Severity: 78%
Audit Metadata