workflow

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Security
SecurityMEDIUM
yolo/SKILL.md

SUSPICIOUS: the stated QA purpose is plausible, but the footprint is too broad and autonomous for that role. The biggest issues are permissionless file deletion/editing including `.env` and dotfiles, plus consuming external review/web content while retaining write and execution powers. No clear evidence of malware or credential theft, but this is a high-impact agent skill that should be tightly constrained.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Sep 1, 2026, 11:09 PM
Package URL
pkg:socket/skills-sh/blockmatic%2Fbasilic-skills%2Fworkflow%2F@8279ca38f191628138b16117b054da65c08ddd2c991a95e07eef18edc5e265f9
Security Audit — socket — workflow