epic-workflow

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core GitHub planning workflow is coherent and uses official git/gh tooling, but the skill is not fully benign because it chains into unspecified helper skills, reads broad repository content, and performs autonomous external actions (issue creation and branch push) without explicit per-action approval. Main risk is transitive trust and prompt-injection/autonomy exposure, not confirmed malware.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Mar 21, 2026, 11:52 PM
Package URL
pkg:socket/skills-sh/CosticaPuntaru%2FagenTica%2Fepic-workflow%2F@930b44344d291b8ffb047bff9f77baba2e7b1fec
Security Audit — socket — epic-workflow