idea-creator

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core ideation and literature-review behavior is legitimate, and the OpenAI Codex path is plausible, but the skill is over-scoped: it has Bash(*) wildcard access, can orchestrate pilot experiments, mutates wiki/report files, uses opaque local helper scripts with unverifiable provenance, and includes a 'do it silently' directive. No confirmed credential theft or malicious payload is present, but the capability footprint is broader and riskier than a simple idea-generation skill.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 17, 2026, 01:27 AM
Package URL
pkg:socket/skills-sh/wanshuiyin%2FAuto-claude-code-research-in-sleep%2Fidea-creator%2F@e895774b913b61a83e1fa02485b6377c083a5c0f
Security Audit — socket — idea-creator