research-orchestrator

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's capabilities broadly match a research orchestrator, but its footprint is high-risk for an AI agent because it combines untrusted content ingestion with Bash, file writes, and delegated subagents. The strongest concern is indirect prompt injection and transitive trust in other skills/CLIs, not clear evidence of credential theft or malicious exfiltration.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Apr 14, 2026, 09:53 AM
Package URL
pkg:socket/skills-sh/TorpedoD%2Fresearch-pipeline%2Fresearch-orchestrator%2F@a81e49ad83039526f6148dcb1074fe3b644011d0
Security Audit — socket — research-orchestrator