autoresearch

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned for autonomous optimization, but it grants an agent persistent self-directed execution with destructive git resets and arbitrary local command runs. No explicit credential theft, exfiltration, or untrusted external installer is present, so this is not malicious; the main risk is high-impact autonomy over a local repo.

Confidence: 87%Severity: 71%
Audit Metadata
Analyzed At
Apr 13, 2026, 10:42 PM
Package URL
pkg:socket/skills-sh/Factory-AI%2Ffactory-plugins%2Fautoresearch%2F@9c08504625091b5582b0bc3283a1cb4c64e96ca1