grok-worker
Warn
Audited by Socket on Aug 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose and capabilities mostly align: using Cursor CLI to run a one-shot Grok worker for alternate implementation/debugging is coherent. Main risks are execution breadth (`--yolo --trust`, optional disabled sandbox/MCP approval) and indirect prompt-injection exposure from repository content, not overt credential theft or off-platform exfiltration. Overall this is a high-trust automation skill with medium security risk, but not malicious based on the provided evidence.
Confidence: 88%Severity: 56%
Audit Metadata