research-workflow
Warn
Audited by Socket on Feb 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is coherent and aligned with its stated purpose: orchestrating research pipelines using ExoPriors/Scry services. I found no signs of obfuscation, hidden backdoors, or credential-harvesting redirects. The primary security considerations are operational: protect the EXOPRIORS_API_KEY (private keys allow write operations that persist data and publish shares), avoid placing secrets in payloads or temporary files, and enforce human review before an agent writes/publishes results. Overall the skill appears benign in intent but requires careful key management and cautious handling of untrusted corpus content to avoid accidental data exposure.
Confidence: 90%Severity: 75%
Audit Metadata