worklog

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is locally scoped and uses no external downloads, credentials, or network exfiltration, so it is not malware-like. However, its actual footprint is broader than a simple worklog viewer: it silently installs a persistent Claude hook that captures future prompts, creating ongoing privacy-sensitive logging behavior that is only partly proportional to the stated review purpose.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:36 PM
Package URL
pkg:socket/skills-sh/wilmanbarrios%2Fskills%2Fworklog%2F@18c3cdafcb27c2de86bf027615a4ec64e99975e9