workbench

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The workbench fragment describes a coherent, container-based isolation workflow intended to safely develop and test code. Its security model (non-privileged container, explicit approvals for build/run, and host-mounted workspace) is proportionate to the task and reduces surface area for host compromise. Risks are present (container CVEs, potential data leakage via shared mounts, dependency supply-chain risk) but are acknowledged and mitigated by the explicit workflow controls. Overall, the design is benign and purpose-aligned with moderate, manageable security risk.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:25 PM
Package URL
pkg:socket/skills-sh/nielsmadan%2Fagentic-coding%2Fworkbench%2F@1827fddcb50d0511da687f6d86f81f935cd0e964