workspace-setup

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core workspace/file sync behavior is broadly aligned with the stated purpose, but the skill has two notable risk amplifiers: plaintext FileBrowser credentials and explicit transitive skill installation/sync via npx skills and remote skills directories. Because the CLI path is same-org official, this is not strong evidence of malware, but it is a medium-to-high security risk due to mutable installs and inherited trust in additional skills.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 21, 2026, 05:50 AM
Package URL
pkg:socket/skills-sh/ANIAN0%2Fpick-skills%2Fworkspace-setup%2F@d46167dbbcea5b09a50eeceb667ce82719c18982