daily-cowork-backup
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s backup purpose broadly matches its file access, but its data-flow design is weak: it sends sensitive archives and an API key to a URL taken from config rather than a verified official endpoint, and it includes that credential-bearing config inside the backup itself. Reliance on Desktop Commander for host-side execution is plausible for the stated environment, but it expands trust and impact. High security risk, but not enough evidence of confirmed malicious intent.
Confidence: 90%Severity: 76%
Audit Metadata