autoresearchclaw-autonomous-research

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's broad autonomy and code-execution capabilities fit its stated research purpose, but the trust model is weak: it asks users to install and execute a GitHub repo from a different org than the skill publisher, and it strongly encourages --auto-approve despite generating and running code from externally sourced research inputs. Data flows mostly match the described workflow and do not show obvious credential exfiltration to unrelated endpoints, so this is not confirmed malware, but it is a high-trust autonomous skill with medium-high security risk.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Sep 12, 2026, 08:29 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Ftrending-skills%2Fautoresearchclaw-autonomous-research%2F@fc5f173193f5f4ca2dde315cbfe971ca7a9dbaf681e00279e63eb169ae621354
Security Audit — socket — autoresearchclaw-autonomous-research