researcher

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose and visible capabilities mostly align with a research skill, and there is no explicit credential theft, malware payload, or unsafe installer. Risk comes from two coherence issues: it processes untrusted web content while retaining write access, and it relies on unverified transitive skills/internal functions like /document-hunter and researchers-* that are not defined here. This is better classified as a high-risk research/automation skill rather than confirmed malicious content.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Mar 27, 2026, 11:27 PM
Package URL
pkg:socket/skills-sh/bitwize-music-studio%2Fclaude-ai-music-skills%2Fresearcher%2F@2c5e9ea715af54793998732a8e8b08eacca985d5