autoresearch

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s research-orchestration purpose broadly matches its file, git, literature, and reporting actions, but it crosses into high-risk territory by mandating continuous autonomous operation, forbidding per-action confirmation, enabling proactive outbound messaging, and delegating to other skills/tools. Install trust is mixed: OpenClaw references appear same-org and official, so this is not confirmed malware, but the overall footprint is high-risk and disproportionate for a skill meant to manage research.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Apr 30, 2026, 05:59 AM
Package URL
pkg:socket/skills-sh/zechenzhangagi%2Fclaude-ai-research-skills%2Fautoresearch%2F@76cb8a177fe98fa541f1ae10cf993e2e37eff7ec