research-review
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s review/export behavior is broadly consistent with its stated purpose, and the autonomy-abuse finding looks like a false positive. However, it relies on an unverifiable local MCP server and opaque external backend routing for potentially sensitive research content, so the install trust and data-flow footprint are high enough to make the skill risky even without clear malicious intent.
Confidence: 88%Severity: 78%
Audit Metadata