workspace-status

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s behavior mostly matches its stated workspace-diagnostics purpose: it reads expected config/env files, compares local registry state, and probes MCP availability. The main risk is trust in several unverifiable local scripts plus broader-than-necessary tool permissions for a diagnostic skill. This looks suspicious/high-risk from an execution-trust standpoint, but not malicious: no clear credential exfiltration, no third-party relay, and no deceptive purpose mismatch were found.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Jul 25, 2026, 01:53 PM
Package URL
pkg:socket/skills-sh/cogni-work%2Finsight-wave%2Fworkspace-status%2F@c45d3bc69990680df9faddcec702bddef9e258f290d630615b6b742e384007de
Security Audit — socket — workspace-status