autoresearch

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s research capabilities mostly match its stated purpose, but its footprint is high-risk for an AI agent: broad tool access, autonomous Bash execution, delegated agents, and heavy processing of untrusted external content create a strong indirect prompt-injection and autonomy risk. Install trust is also only moderate because the skill appears to come from a personal GitHub publisher with no visible release verification. No clear credential harvesting or explicit exfiltration is present, so this is not confirmed malware.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:59 PM
Package URL
pkg:socket/skills-sh/ThePickleGawd%2Fautoresearch-skill%2Fautoresearch%2F@15a5cf6bef1c55984416bc6691fee4cfdf230595