research-workflow

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is coherent and aligned with its stated purpose: orchestrating research pipelines using ExoPriors/Scry services. I found no signs of obfuscation, hidden backdoors, or credential-harvesting redirects. The primary security considerations are operational: protect the EXOPRIORS_API_KEY (private keys allow write operations that persist data and publish shares), avoid placing secrets in payloads or temporary files, and enforce human review before an agent writes/publishes results. Overall the skill appears benign in intent but requires careful key management and cautious handling of untrusted corpus content to avoid accidental data exposure.

Confidence: 90%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 08:33 AM
Package URL
pkg:socket/skills-sh/exopriors%2Fskills%2Fresearch-workflow%2F@bc1ddb390805aeb0e79ae09de83026c676a36ff4