codex-autoresearch-loop

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core purpose is autonomous code modification, but its footprint is unusually broad and high-risk: unbounded unattended execution, automatic git actions, external web-search escalation, and transitive remote skill installation. The ara.so branding versus third-party GitHub install source further weakens trust, so this should not be treated as a benign documentation-only skill.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Mar 21, 2026, 05:26 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fcodex-autoresearch-loop%2F@a67ae3ca8cebb5caa7f74ced24d164245e20cf7c