ASCN operator

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md describes an operator whose stated purpose (deterministic management of MCP workspace workflows) aligns with its requested capabilities: discovery, validation, mutation, activation, export, and verification via the control.* tool surface. There are no indicators of code-execution, obfuscated payloads, download-and-run instructions, or credential exfiltration flows to third-party domains. Primary risks are operational and supply-chain: the operator requires a workspace secret (mcp_gateway_token) and high-privilege control APIs; misuse or compromised agent runtime/tool mapping could allow destructive changes. The hardcoded dev gateway URL is an operational footgun if copied into production. Overall this appears to be a legitimate operator spec with expected high-impact privileges; treat it as sensitive (review permissions, restrict secret access, and ensure gateway endpoint configuration is verified before use).

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 07:57 AM
Package URL
pkg:socket/skills-sh/ascnai%2Fnocodeskill%2Fascn-operator%2F@1e35242c3b2742558f3c4b24ad8e1b0ef9fe29de