openwork
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is coherent as a marketplace integration, and data flows go to the claimed Openwork domain rather than an unrelated proxy. However, it grants an AI agent autonomous financial and platform actions without human approval, fetches mutable remote skill content, and exposes the agent to untrusted marketplace content that can influence later actions.
Confidence: 90%Severity: 78%
Audit Metadata