research

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent for UX research, but the skill expands trust through unreviewed local skills and an optional preflight script, and it combines broad untrusted-content ingestion with possible shell/local-context access. No direct malware, credential harvesting endpoint, or third-party installer is shown, so this is not malicious on the provided evidence, but it carries medium security risk and high prompt-injection exposure.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 06:13 AM
Package URL
pkg:socket/skills-sh/openai%2Frole-specific-plugins%2Fresearch%2F@e83d48ed9d927bae4b57839080562277c40742bb992fdcc0e54ebcbea0d9b647
Security Audit — socket — research