unified-execute-with-file

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s overall purpose is coherent for a workflow executor, but its footprint is high-risk because it treats plan JSON as executable authority. Untrusted task content can drive Bash commands, file modifications, network-capable verification, commits, and transitive skill actions; this is disproportionate unless plans are fully trusted.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Mar 25, 2026, 11:05 AM
Package URL
pkg:socket/skills-sh/catlog22%2FClaude-Code-Workflow%2Funified-execute-with-file%2F@1309f70f9694cc96a099a622d283e683308cd945
Security Audit — socket — unified-execute-with-file