ascn-operator

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The ascn-operator skill describes a governance-heavy orchestration component that relies on a well-defined set of internal MCP control tools and a trusted MCP gateway. Its footprint is coherent with a legitimate operator role: it requires workspace-specific secrets, performs formal validation steps, and adheres to explicit mutation and error-handling workflows. The external MCP gateway dependency is a normal part of its architecture but introduces external trust considerations; as long as the gateway and secret management are properly secured, the risk remains Moderate and proportionate to its purpose. No evident credential harvesting, data exfiltration, or autonomous real-world actions are described. Overall, the risk posture appears Benign to Suspect (leaning Benign) with moderate security risk due to external dependency surface and sensitive secret handling.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 10:47 PM
Package URL
pkg:socket/skills-sh/ascnai%2Fskills%2Fascn-operator%2F@b1b085365edb1675440dda85d2faf12e445f6417