autoresearch-agent

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s footprint matches its stated purpose, but that purpose is itself high-risk: it is a wrapper for autonomous headless Claude execution with permission checks intentionally bypassed, and it chains trust into another skill whose behavior is not included here. This is not confirmed malware, but it is a materially risky automation skill that should only run in tightly controlled environments.

Confidence: 82%Severity: 76%
Audit Metadata
Analyzed At
Mar 24, 2026, 02:05 AM
Package URL
pkg:socket/skills-sh/tumf%2Fskills%2Fautoresearch-agent%2F@f617a03b926a1847140de75c701dfc2c2b4d97be