workspace-setup
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose is legitimate and the main tools are standard, but it grants the agent authority to execute arbitrary shell commands extracted from WORKSPACE.md and repo-controlled npm scripts. That is proportionate to setup automation yet materially risky because trust is delegated to unvalidated local content and third-party dependency scripts.
Confidence: 85%Severity: 56%
Audit Metadata