ws-workflow-engine-bridge

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, and there is no installer or obvious credential-harvesting path, but it executes externally authored prompt workflows with access to rich AuthorClaw context and file writes. The main risk is indirect prompt injection and unintended disclosure of project data through model routing, not confirmed malware.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 18, 2026, 12:44 AM
Package URL
pkg:socket/skills-sh/Ckokoski%2Fauthorclaw%2Fws-workflow-engine-bridge%2F@051fe69a564acfdd2f62dbb58d460025639a3308
Security Audit — socket — ws-workflow-engine-bridge