research-pipeline

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent for autonomous research automation, but its footprint is high-risk and overbroad. Wildcard Bash access, remote experiment deployment, autonomous multi-hour action loops, external content ingestion with write/exec capability, transitive skill chaining, and silent execution behavior make it risky even without clear evidence of credential theft or malicious exfiltration.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Apr 19, 2026, 03:15 AM
Package URL
pkg:socket/skills-sh/Shaun-Z%2FAuto-claude-code-research-in-sleep%2Fresearch-pipeline%2F@21b8baf6f1cd5cb5ec2ea758fe45fe9dc5606043