ws-workflow-engine-bridge
Warn
Audited by Socket on Apr 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's core purpose is coherent, and there is no installer or obvious credential-harvesting path, but it executes externally authored prompt workflows with access to rich AuthorClaw context and file writes. The main risk is indirect prompt injection and unintended disclosure of project data through model routing, not confirmed malware.
Confidence: 84%Severity: 52%
Audit Metadata