autoresearchclaw-autonomous-research
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's broad autonomy and code-execution capabilities fit its stated research purpose, but the trust model is weak: it asks users to install and execute a GitHub repo from a different org than the skill publisher, and it strongly encourages --auto-approve despite generating and running code from externally sourced research inputs. Data flows mostly match the described workflow and do not show obvious credential exfiltration to unrelated endpoints, so this is not confirmed malware, but it is a high-trust autonomous skill with medium-high security risk.
Confidence: 88%Severity: 74%
Audit Metadata