auto-benchmark

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's stated purpose matches benchmarking and research tracking, but it gives an AI agent a broad autonomous loop over untrusted external content plus local execution, config mutation, reporting, and possible external submissions. There is no clear credential theft or malicious install path, so this is not confirmed malware, but it is a high-impact automation skill that should require strong human approval boundaries.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:16 AM
Package URL
pkg:socket/skills-sh/aviskaar%2Fopen-org%2Fauto-benchmark%2F@30307452e8bf46436acae601211c51e448c583a4