workhub

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the Workhub skill description and usage demonstrate coherent purpose-capability alignment. It focuses on local document/workflow management with a clear SSOT model and GitHub-style workflows, without introducing external network calls, credential handling, or unverifiable binaries. Data flows are contained within the project workspace (docs/), which supports secure, predictable operation aligned with its stated goals. The footprint is benign and proportionate to its purpose. As a precaution, ensure future extensions do not introduce shell command execution from untrusted input or external data exfiltration paths.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:24 AM
Package URL
pkg:socket/skills-sh/dwsy%2Fagent%2Fworkhub%2F@929ee06055d6e46f6d01d481ed759308037dee0f