new-workspace
Warn
Audited by Socket on Jul 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is mostly coherent for workspace provisioning, using official GitHub tooling and standard git flows, so it does not look malicious. The main risk is scope and privacy: it reads global user memory, creates public repositories by default, and auto-publishes metadata to a personal-account public index, enabling outward actions and possible unintended disclosure beyond a local scaffold task.
Confidence: 87%Severity: 63%
Audit Metadata