wrk

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Suspicious but not clearly malicious. The skill's install path is relatively legitimate, but its main trust model sends Wrk interactions through Membrane as an intermediary rather than directly to Wrk, and the broken 'official docs' reference undermines coherence. Main risk is third-party credential/data mediation and mutable CLI installs, not confirmed malware.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Apr 28, 2026, 11:51 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwrk%2F@d956327c53dfd41e54b47d947085913dbfa9e8ec
Security Audit — socket — wrk