st-full-workflow

Warn

Audited by Socket on Jun 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the workflow is mostly purpose-aligned and uses local relative scripts, but it grants broad autonomous repository-changing behavior and executes instructions sourced from project-local markdown hooks. The main trust gap is indirect instruction execution from repository content plus an unverifiable, unpinned npx initializer mentioned as the setup path.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 14, 2026, 02:12 PM
Package URL
pkg:socket/skills-sh/e0ipso%2Fstrikethroo%2Fst-full-workflow%2F@ed7e15afb7a06aca2c2833b1c197a6a748c8e49719cec2c6b27ef85833acdd49
Security Audit — socket — st-full-workflow