workon

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it grants an agent autonomous issue/repo workflow actions and forwards untrusted issue content into another agent’s instruction channel, creating meaningful prompt-injection and automation risk. No clear credential theft or overt exfiltration is shown, so this is not malware, but it is a medium-to-high risk orchestration skill.

Confidence: 83%Severity: 68%
Audit Metadata
Analyzed At
Mar 19, 2026, 02:09 PM
Package URL
pkg:socket/skills-sh/soul-brews-studio%2Foracle-skills-cli%2Fworkon%2F@f760ee4e0616e4c2bd9053fd8429f849d05f546d