workflow-migration

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent for migration orchestration, but its real behavior is mostly opaque because it triggers a long chain of external workflow commands. Risk comes from transitive trust and forced sequential execution, not from direct credential theft or explicit exfiltration in this file.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
Apr 10, 2026, 07:28 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fworkflow-migration%2F@94edaefd172affaff306148bb928f5b5e91fc950
Security Audit — socket — workflow-migration