skill-from-research
Warn
Audited by Socket on Jul 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose and local file-writing behavior are coherent for a research-to-skill authoring workflow, and it does not request secrets or exfiltrate data. The main security concern is the instruction to install another skill from a third-party repo via npx, creating a transitive trust chain; untrusted pack ingestion also carries moderate prompt-injection risk despite good guardrails.
Confidence: 88%Severity: 58%
Audit Metadata