workflow-greenfield-init

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent as a workflow orchestrator, but it grants broad autonomous execution across research, planning, coding, testing, and docs with little visible gating. Main risk is recursive/indirect prompt injection from web research combined with downstream file and execution actions, not confirmed malware or credential theft.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
Apr 10, 2026, 07:28 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fworkflow-greenfield-init%2F@9347f4147eae0b2696359c17b4f159d72f30dd29
Security Audit — socket — workflow-greenfield-init