wiki-work

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core task-generation behavior is coherent and mostly local, but the preamble introduces external `npx` execution and a conditional global installation of another skill, creating a transitive trust risk disproportionate to a simple planning skill. No clear credential harvesting or exfiltration is present, so this is not confirmed malware, but it carries meaningful supply-chain and trust-boundary risk.

Confidence: 83%Severity: 66%
Audit Metadata
Analyzed At
Apr 1, 2026, 12:28 AM
Package URL
pkg:socket/skills-sh/dev-goraebap%2Fdot-wiki%2Fwiki-work%2F@2759f0cdb01f12e0667ec2182c64f45b43bac814
Security Audit — socket — wiki-work