research-pipeline

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose is coherent for research automation, but its footprint is high-risk: broad Bash(*) access, autonomous remote experiment actions, ingestion of untrusted external content while retaining write/exec powers, and a directive to act silently. Install provenance is mostly benign from the provided evidence, so the main concern is unsafe autonomy and data/action flow breadth rather than confirmed malware.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Apr 18, 2026, 10:26 AM
Package URL
pkg:socket/skills-sh/wanshuiyin%2FAuto-claude-code-research-in-sleep%2Fresearch-pipeline%2F@21b8baf6f1cd5cb5ec2ea758fe45fe9dc5606043