lead-researcher

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches a research-orchestration role, but it expands trust by explicitly delegating to many other skills and may process untrusted external research content while potentially triggering replication/execution through sub-skills. No direct credential harvesting, exfiltration endpoint, or mismatched data flow is present here; the main risks are transitive skill trust, prompt-injection exposure from external content, and minor official-installer supply-chain risk around optional Ollama use.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:17 AM
Package URL
pkg:socket/skills-sh/aviskaar%2Fopen-org%2Flead-researcher%2F@2334ee412241da28b1b3782cbb8f4bb6a4045ea3