active-research

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment represents a coherent, well-structured skill specification for an AI agent to perform literature research and generate structured reports using a browser automation workflow (Actionbook) and a json-ui renderer. There are no evident malicious intents or credential harvesting patterns. The data flows align with the stated purpose (topic input -> browse/search -> extract/synthesize -> output report). The primary concerns are typical supply-chain risks associated with using external tooling and public registries, not direct malware or data exfiltration. The design is benign but moderately complex; ensure proper access controls, source verification, and that output does not inadvertently leak sensitive user-generated topics or restricted content.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/actionbook%2Factionbook%2Factive-research%2F@347266cca0a486443e26b63450a22aac00b75201