robonet-workbench

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This document is a skill specification describing a high-privilege trading/workbench integration (Robonet MCP). There is no direct evidence of malware or obfuscated code in the text. The primary risks are operational and supply-chain/trust related: the skill requires API keys and wallet credentials and routes many sensitive operations through a third-party MCP server (possible credential exposure or centralized data access). Before use, confirm whether wallet private keys ever leave the user's environment, examine Robonet's security/retention policy, and restrict agent/tool permissions (require human confirmation before deployments or spending). Treat the skill as SUSPICIOUS from a supply-chain/trust perspective (requires strong vetting) but not overtly malicious.

Confidence: 70%Severity: 60%
Audit Metadata
Analyzed At
Feb 16, 2026, 02:09 AM
Package URL
pkg:socket/skills-sh/robonet-tech%2Fskills%2Frobonet-workbench%2F@782994df34727bfd81c2864edf7d7878c83f98db