execute-work-package
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the workflow purpose is coherent, but the default MCP path relies on an unverifiable local l4l_oci dependency that receives API keys and potentially repo data. The gating model reduces autonomy risk, yet install/provenance and credential-forwarding concerns make the skill high risk even without confirmed malware.
Confidence: 84%Severity: 84%
Audit Metadata