researcher
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The researcher skill presents a coherent architecture for sharded, staged repository analysis with explicit start/approve workflow and a clear source-to-sink data path. The main concern is the unverifiable binary/runtime (xiuxian-qianji) used as the execution backend, with no explicit provenance, checksum, or registry source in the provided material. This introduces a potential supply-chain risk and warrants requiring verifiable artifacts or official registry installation details before deployment. Overall, the footprint is proportionate to the stated purpose, but trust controls around the external runtime and any hidden network endpoints should be clarified.
Confidence: 98%
Audit Metadata