ASCN operator
Audited by Socket on Feb 25, 2026
1 alert found:
SecurityThis SKILL.md describes an operator whose stated purpose (deterministic management of MCP workspace workflows) aligns with its requested capabilities: discovery, validation, mutation, activation, export, and verification via the control.* tool surface. There are no indicators of code-execution, obfuscated payloads, download-and-run instructions, or credential exfiltration flows to third-party domains. Primary risks are operational and supply-chain: the operator requires a workspace secret (mcp_gateway_token) and high-privilege control APIs; misuse or compromised agent runtime/tool mapping could allow destructive changes. The hardcoded dev gateway URL is an operational footgun if copied into production. Overall this appears to be a legitimate operator spec with expected high-impact privileges; treat it as sensitive (review permissions, restrict secret access, and ensure gateway endpoint configuration is verified before use).