workspace-doctor

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/doctor.sh

The strongest security issue in this fragment is arbitrary command execution via eval "$check" where $check originates from the workspace configuration (“## Health Checks”). If CONFIG_FILE (or the surrounding workspace configuration supply chain) can be modified by an attacker, this script becomes a direct sabotage/remote execution mechanism. Additionally, the script sources workspace-utils.sh, expanding trust to another executable module. No explicit data theft/exfiltration/backdoor indicators are visible in this file alone, but the eval-based design materially increases supply-chain security risk.

Confidence: 68%Severity: 73%
Audit Metadata
Analyzed At
Mar 27, 2026, 08:08 PM
Package URL
pkg:socket/skills-sh/patricio0312rev%2Fworkspaces%2Fworkspace-doctor%2F@d38159ed339f9d4370401062ed0923132d5e80a5