bookstrap-research
Warn
Audited by Socket on Apr 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is largely purpose-aligned for autonomous research, with no strong malware or supply-chain indicators, but it combines autonomous web ingestion of untrusted content with Bash/Write access and local state changes. Plaintext local DB credentials and optional routing through Serper add medium risk, making this a high-risk research automation skill rather than a clearly malicious one.
Confidence: 88%Severity: 74%
Audit Metadata