research-review

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s review/export behavior is broadly consistent with its stated purpose, and the autonomy-abuse finding looks like a false positive. However, it relies on an unverifiable local MCP server and opaque external backend routing for potentially sensitive research content, so the install trust and data-flow footprint are high enough to make the skill risky even without clear malicious intent.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:10 PM
Package URL
pkg:socket/skills-sh/wanshuiyin%2Fauto-claude-code-research-in-sleep%2Fresearch-review%2F@76b226fe9eaab878bcce2f008ac6abe45089021f00b881d8099678c8217d43f1
Security Audit — socket — research-review