ai-automation-workflows

Warn

Audited by Socket on Jul 27, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

SUSPICIOUS: overall coherent with AI workflow automation, and the installer appears to be official same-org infrastructure rather than an unrelated third party. Risk comes from pipe-to-shell installation, broad Bash/CLI execution, optional webhook forwarding of command output, and transitive installation of other skills; these are proportionate enough to avoid a malicious classification but raise medium security concern.

Confidence: 89%Severity: 56%
SecurityMEDIUM
skill-report.json

Overall security posture is high-risk from an operational/supply-chain-use perspective. The material contains a critical pipe-to-shell remote installer pattern, guidance that can enable cron-based recurring execution, and templates that can transmit unredacted local file contents and captured command/error output to external services/webhooks. While this appears to be documentation/templates rather than covert embedded malware, following or copy/pasting these commands can result in arbitrary code execution (if the installer endpoint is compromised) and sensitive data disclosure (if local files or stderr contain secrets).

Confidence: 62%Severity: 82%
Audit Metadata
Analyzed At
Jul 27, 2026, 04:26 AM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fai-automation-workflows%2F@6de9e23d176c347669546b20d49d0dd8500148173e904050bc7c2f09bd4fd8e5
Security Audit — socket — ai-automation-workflows