autoresearch

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose mostly matches its capabilities, but its footprint is high-risk because it grants an AI agent indefinite autonomous code-editing and command-execution authority over arbitrary projects, with destructive git cleanup and strong exposure to untrusted repo content and project scripts. No clear credential harvesting or explicit exfiltration is present, so this is better classified as a dangerous autonomous developer workflow than confirmed malware.

Confidence: 88%Severity: 81%
Audit Metadata
Analyzed At
Mar 20, 2026, 11:30 PM
Package URL
pkg:socket/skills-sh/PaulRBerg%2Fagent-skills%2Fautoresearch%2F@8a887c8e201477a91213a48170e3f49a92e71676