ai-to-tickets-workplan
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the workflow is purpose-consistent for ticket publication, but it relies on an unverified `wp` CLI and a second unverified skill, and it performs autonomous external mutations without another approval step. No direct credential theft or overt exfiltration is shown, so this is not confirmed malware, but the trust chain and opaque binary/backend make it high risk.
Confidence: 81%Severity: 76%
Audit Metadata