octocode-researcher

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose mostly matches its research capabilities, but it combines unpinned `npx` execution of a third-party MCP server with broad ingestion of untrusted external content and local write/clone capabilities. This looks more like a high-risk research automation skill than malware; the main concerns are supply-chain trust and indirect prompt-injection exposure, not overt credential theft or exfiltration.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Mar 17, 2026, 08:11 AM
Package URL
pkg:socket/skills-sh/bgauryy%2Foctocode-mcp%2Foctocode-researcher%2F@a9924b1f0604a39c5322ecaebc4b4c794d839a2c