research

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is legitimate, but the actual footprint is broader than a simple research skill: it executes multiple unverified local/external tools, proxies web fetches through third-party services, and processes untrusted external content while retaining shell and file-write capabilities. The strongest concern is data-flow integrity and execution trust, not confirmed malware.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
May 5, 2026, 09:08 AM
Package URL
pkg:socket/skills-sh/stevengonsalvez%2Fagents-in-a-box%2Fresearch%2F@8b83681ff35b5a8ad40398b5e320390f3f2810ff