auto-researching

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core behavior is an indefinite autonomous experiment loop that modifies code, runs repository-derived commands, and continues without further user approval. There is no clear credential theft or malware payload, but the autonomy and exec scope are disproportionate and create high operational risk.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Mar 27, 2026, 03:26 PM
Package URL
pkg:socket/skills-sh/tylergibbs1%2Fcodeskills%2Fauto-researching%2F@b2135a29304c95a3c39371d67a37128cecfcb2cb
Security Audit — socket — auto-researching