research-lit

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent, but the footprint is broader than needed and relies on unverified third-party MCP servers for access to private research notes and annotations. Main risks are overbroad Bash permission and indirect prompt-injection/data-routing exposure rather than confirmed malicious behavior.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Mar 15, 2026, 06:42 AM
Package URL
pkg:socket/skills-sh/wanshuiyin%2Fauto-claude-code-research-in-sleep%2Fresearch-lit%2F@8a81383f2bcd6dc4fb38d97c801b157178b26e24