research-pipeline
Warn
Audited by Socket on Apr 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent for autonomous research automation, but its footprint is high-risk and overbroad. Wildcard Bash access, remote experiment deployment, autonomous multi-hour action loops, external content ingestion with write/exec capability, transitive skill chaining, and silent execution behavior make it risky even without clear evidence of credential theft or malicious exfiltration.
Confidence: 88%Severity: 82%
Audit Metadata