coding-workflow

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core workflow guidance is benign and proportionate, but the skill expands trust by instructing installation of multiple external companion skills, including one with weaker provenance. Main risk is transitive skill installation and moderate remote supply-chain exposure, not direct credential theft or overtly malicious behavior.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Apr 15, 2026, 10:00 AM
Package URL
pkg:socket/skills-sh/borjasolerme%2Fagent-skills%2Fcoding-workflow%2F@d7da5d0c0df4a5f0375d96626b398e1e67b557a1