agentic-workflow
Warn
Audited by Socket on Jul 27, 2026
1 alert found:
SecuritySecurityskill-report.json
MEDIUMSecurityMEDIUM
skill-report.json
No evidence is shown that the package itself contains covert malware logic; however, it includes high-risk supply-chain and credential-exposure guidance. The most significant issue is a remote installer executed via a pipe-to-sh pattern with no integrity verification, compounded by examples that forward API keys into containers while mounting the local workspace. Users who copy/paste these examples are materially exposed if the remote endpoint, downloaded script, or container image is compromised.
Confidence: 66%Severity: 78%
Audit Metadata