autoresearch

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core purpose is coherent, and there is no evidence of credential theft, exfiltration, or malicious installer behavior. The main risk is the autonomous, effectively unbounded loop that repeatedly executes and mutates arbitrary skills, plus minor third-party CDN exposure for the dashboard.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:29 AM
Package URL
pkg:socket/skills-sh/iancleary%2Fdotfiles%2Fautoresearch%2F@59e655a29b8f7b7de089baf91a782639746165d9