scratchpad
Warn
Audited by Socket on Mar 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The Scratchpad skill is potentially useful for isolated experimentation, but it poses notable security concerns due to unverified tooling, autonomous code execution within a shared environment, and potential data/exfiltration paths. It should only be considered BENIGN if the MCP tooling is audited, sandboxing is proven to be strict (no external network/file access beyond the sandbox), and inputs/outputs are tightly restricted to return-only conclusions as advertised. Otherwise, treat as SUSPICIOUS.
Confidence: 62%Severity: 58%
Audit Metadata