NYC

research

Fail

Audited by Socket on Feb 18, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill implements a legitimate research workflow but poses a moderate supply-chain/data-exfiltration risk because it mandates dispatching exploration agents (spawn_agent/TeamCreate/Task/ao) and instructs including file:line citations and code snippets without any sanitization or explicit backend trust model. In trusted environments where backends are local or enterprise-controlled, risk is low; in default or untrusted environments, the workflow can leak sensitive repository contents. Recommend: enforce sanitization and allow/deny lists, require explicit human confirmation before remote dispatch (or disable --auto by default), and document the exact backend endpoints/trust model before use.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 18, 2026, 11:20 AM
Package URL
pkg:socket/skills-sh/boshu2%2Fagentops%2Fresearch%2F@bc2ab9d0290b27f84151c94acdc1a3a15646f46c