workspace-setup

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose is legitimate and the main tools are standard, but it grants the agent authority to execute arbitrary shell commands extracted from WORKSPACE.md and repo-controlled npm scripts. That is proportionate to setup automation yet materially risky because trust is delegated to unvalidated local content and third-party dependency scripts.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Mar 27, 2026, 08:09 PM
Package URL
pkg:socket/skills-sh/patricio0312rev%2Fworkspaces%2Fworkspace-setup%2F@5bb23871d3e194538491b769b7988d080a6f0c5a