st-full-workflow
Warn
Audited by Socket on Jun 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the workflow is mostly purpose-aligned and uses local relative scripts, but it grants broad autonomous repository-changing behavior and executes instructions sourced from project-local markdown hooks. The main trust gap is indirect instruction execution from repository content plus an unverifiable, unpinned npx initializer mentioned as the setup path.
Confidence: 100%Severity: 60%
Audit Metadata