scratchpad

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The Scratchpad skill is potentially useful for isolated experimentation, but it poses notable security concerns due to unverified tooling, autonomous code execution within a shared environment, and potential data/exfiltration paths. It should only be considered BENIGN if the MCP tooling is audited, sandboxing is proven to be strict (no external network/file access beyond the sandbox), and inputs/outputs are tightly restricted to return-only conclusions as advertised. Otherwise, treat as SUSPICIOUS.

Confidence: 62%Severity: 58%
Audit Metadata
Analyzed At
Mar 10, 2026, 12:46 AM
Package URL
pkg:socket/skills-sh/chen19007%2Fmy_skills%2Fscratchpad%2F@68a5311fb7a7a0ef6093b3bcc6a79b1459c60222