autoresearch-ml

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core ML-training behavior mostly matches the stated purpose, and installs appear tied to legitimate tooling, but the skill is high risk because it authorizes indefinite autonomous experimentation, repeated code execution, and ongoing code changes without explicit user approval. Main concern is autonomy abuse and broad execution scope, not confirmed malware or credential theft.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Apr 11, 2026, 09:31 PM
Package URL
pkg:socket/skills-sh/proyecto26%2Fautoresearch-ai-plugin%2Fautoresearch-ml%2F@f6c16111abe00380eca493871b622b87114f5678