workspace-status
Warn
Audited by Socket on Jul 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s behavior mostly matches its stated workspace-diagnostics purpose: it reads expected config/env files, compares local registry state, and probes MCP availability. The main risk is trust in several unverifiable local scripts plus broader-than-necessary tool permissions for a diagnostic skill. This looks suspicious/high-risk from an execution-trust standpoint, but not malicious: no clear credential exfiltration, no third-party relay, and no deceptive purpose mismatch were found.
Confidence: 82%Severity: 72%
Audit Metadata