research

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core purpose is legitimate and mostly aligned, and `gh api` is an official same-org tool. The main concern is data-flow and trust: research requests and possibly multiple provider API keys are routed through a third-party MCP omnisearch server from a personal GitHub account, creating credential-forwarding and prompt-injection risk disproportionate to a simple verification skill.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 01:22 PM
Package URL
pkg:socket/skills-sh/spences10%2Fclaude-code-toolkit%2Fresearch%2F@4fe975c0dffc189c333dc87d33f397db3fb85d6d