wk-self-perf
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s broad data access is mostly aligned with its stated self-review purpose, and there is no clear malicious installer or credential-stealing behavior. The main risk is integrity and confidentiality: it aggregates sensitive workplace data across many systems and then autonomously commits and pushes the corpus, plus it chains into another skill. This is a coherent but overpowered workflow that should require explicit approval before any push or secondary skill invocation.
Confidence: 86%Severity: 68%
Audit Metadata