workflow-e2e-from-changes

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose fits a testing workflow, but the skill is mostly a thin wrapper around opaque slash commands with mandatory sequential execution. There is no direct credential theft or exfiltration evidence, yet the hidden downstream behavior and possible transitive workflow delegation make the overall trust profile medium risk.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
Apr 10, 2026, 07:28 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fworkflow-e2e-from-changes%2F@5bad553c88e8f8426638e65fb92c9d958439383b
Security Audit — socket — workflow-e2e-from-changes