dify-workflow

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s functionality is coherent for Dify workflow editing, but the install trust is weak because the real dependency chain relies on direct GitHub installs, including a personal upstream repo and unpinned mutable refs. No clear credential harvesting or malicious data flow is evident, so this is better classified as supply-chain risk than malware.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
May 8, 2026, 05:53 AM
Package URL
pkg:socket/skills-sh/Akabane71%2Fdify-workflow-cli%2Fdify-workflow%2F@bacb59e9b33cbd3798e0c912c487c4e9dfed42de
Security Audit — socket — dify-workflow