workspace-cli-usage

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities are broadly aligned with an official Chaitin admin CLI, and the install source appears same-org and legitimate. The main security concern is disproportionate transport insecurity: multiple products disable TLS verification by default or unconditionally, which exposes API keys and management actions to interception; combined with high-impact administrative operations, this makes the skill medium-high risk despite low evidence of malicious intent.

Confidence: 93%Severity: 76%
Audit Metadata
Analyzed At
Apr 21, 2026, 12:06 PM
Package URL
pkg:socket/skills-sh/chaitin%2Fworkspace-cli%2Fworkspace-cli-usage%2F@8837f1411ad832789ba3442292902e7227050d30