ta-research-AFP

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core workflow is broadly consistent with a research-writing coordinator, and the only explicit install guidance points to a legitimate PyPI package. However, the skill expands trust transitively to many unnamed external skills, some of which perform web search and citation verification, without provenance or data-flow details. It also auto-reads local project files and executes a local bash/python assembly step. This is not clearly malicious, but the undeclared trust chain and automatic local execution make the footprint larger than a simple coordinator should have.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 9, 2026, 11:43 AM
Package URL
pkg:socket/skills-sh/yipng05-max%2F-skills%2Fta-research-afp%2F@68f31a00444c69afbee9d691fa02bf027b35d291