dev-workflow

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's broad autonomous control is mostly consistent with its stated purpose, but it materially increases risk by invoking other skills transitively, executing repo-defined test scripts, processing untrusted GitHub content, and taking real GitHub actions with limited per-step approval. No clear credential harvesting or covert exfiltration is present, so this is not confirmed malware, but it is a high-trust orchestration skill that should be treated as medium-to-high security risk.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Apr 7, 2026, 02:57 PM
Package URL
pkg:socket/skills-sh/EmersonBraun%2Fskills%2Fdev-workflow%2F@d6277c9b3f9479df10a3fb083f81542b3a99bc45
Security Audit — socket — dev-workflow