workspace-guide

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core skill is mostly benign workspace documentation guidance, but it includes transitive skill-install instructions to an unverified third-party publisher. The official CLI path lowers supply-chain concern for the installer, yet the added trust chain is not necessary for the stated purpose and raises medium risk.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Mar 16, 2026, 01:01 AM
Package URL
pkg:socket/skills-sh/tacuchi%2Fworkspace-tools%2Fworkspace-guide%2F@dde532364103e33bf3cf1f6e1412d65f182ca8ab