workflow-full-feature-lifecycle
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated purpose matches a workflow orchestrator, but it forces a long autonomous sequence of opaque commands with unclear downstream permissions. No direct credential theft, exfiltration, or malicious installer is present in the skill text, yet the mandatory execute-all behavior and hidden command implementations make it higher-risk than a simple documentation or helper skill.
Confidence: 80%Severity: 58%
Audit Metadata