agentic-workflow

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Security
SecurityMEDIUM
skill-report.json

No evidence is shown that the package itself contains covert malware logic; however, it includes high-risk supply-chain and credential-exposure guidance. The most significant issue is a remote installer executed via a pipe-to-sh pattern with no integrity verification, compounded by examples that forward API keys into containers while mounting the local workspace. Users who copy/paste these examples are materially exposed if the remote endpoint, downloaded script, or container image is compromised.

Confidence: 66%Severity: 78%
Audit Metadata
Analyzed At
Jul 27, 2026, 04:18 AM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fagentic-workflow%2F@57a0ab694a0fef8190398a75c80a013c1d866eeb968184a207ff433fb3b436b3
Security Audit — socket — agentic-workflow