workflow-tdd-feature

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill itself is a thin workflow orchestrator with no explicit credential theft or exfiltration, but it delegates substantial authority to opaque downstream slash commands with unclear provenance and forces broad sequential execution. Risk is mainly from transitive trust and autonomous multi-step action, not confirmed malware.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Apr 10, 2026, 07:28 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fworkflow-tdd-feature%2F@87a9f21f6de64927a62019c8fed125abcb8d680e
Security Audit — socket — workflow-tdd-feature