new-workspace

Warn

Audited by Socket on Jul 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent for workspace provisioning, using official GitHub tooling and standard git flows, so it does not look malicious. The main risk is scope and privacy: it reads global user memory, creates public repositories by default, and auto-publishes metadata to a personal-account public index, enabling outward actions and possible unintended disclosure beyond a local scaffold task.

Confidence: 87%Severity: 63%
Audit Metadata
Analyzed At
Jul 4, 2026, 11:16 PM
Package URL
pkg:socket/skills-sh/danielrosehill%2FClaude-Research-Space-Plugin%2Fnew-workspace%2F@689f73964f1fadea6e580640629ec8e83476fea80132b22228ca38931f61abc7
Security Audit — socket — new-workspace