execute-work-package

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow purpose is coherent, but the default MCP path relies on an unverifiable local l4l_oci dependency that receives API keys and potentially repo data. The gating model reduces autonomy risk, yet install/provenance and credential-forwarding concerns make the skill high risk even without confirmed malware.

Confidence: 84%Severity: 84%
Audit Metadata
Analyzed At
Aug 20, 2026, 08:08 PM
Package URL
pkg:socket/skills-sh/flitzrrr%2Fagent-skills%2Fexecute-work-package%2F@f74ae8d8d72e56d902dd701001c2c3338c45d9d945756ff806c3d8c570a4ba12
Security Audit — socket — execute-work-package