workflow-verification

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated workflow purpose is plausible, but it is an opaque orchestrator that compels a long sequence of downstream commands with likely read/write/test capabilities and no clear per-action approval. There is no direct credential theft or exfiltration shown, but the unspecified slash-command runtime and broad autonomous execution make the skill medium risk.

Confidence: 79%Severity: 61%
Audit Metadata
Analyzed At
Apr 10, 2026, 07:28 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fworkflow-verification%2F@cf5a07fc8800369c8a99d2b001c028d3810d7b39
Security Audit — socket — workflow-verification