research-pipeline

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent for a research automation skill, but its actual footprint is broad and high-risk. Unrestricted Bash, remote deployment, transitive downstream skills, autonomous long-running loops, and ingestion of untrusted web content together create significant security exposure even without explicit malware or credential theft behavior in this file.

Confidence: 87%Severity: 79%
Audit Metadata
Analyzed At
Mar 17, 2026, 07:06 AM
Package URL
pkg:socket/skills-sh/wanshuiyin%2Fauto-claude-code-research-in-sleep%2Fresearch-pipeline%2F@c6029c241d72e0921b27b472464f3c6283a7b971