research
Warn
Audited by Socket on Apr 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core behavior mostly matches its stated research purpose, and there is no obvious credential harvesting or third-party download chain. The main concern is proportionality: a research skill with Bash, Write, optional WebSearch, and mandatory subagent dispatch can process untrusted content and then take actions, which creates moderate prompt-injection and autonomy risk even without clear malicious intent.
Confidence: 82%Severity: 58%
Audit Metadata