write-workflow

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose mostly matches its workflow behavior, but its trust model is weak: it requires installing and delegating to external third-party skills from GitHub, creating medium-high supply-chain and transitive trust risk. No direct credential harvesting or exfiltration is present in this host file, but the external dependency chain makes the skill suspicious rather than fully benign.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Aug 20, 2026, 07:40 AM
Package URL
pkg:socket/skills-sh/fudesign2008%2Fopen-skills%2Fwrite-workflow%2F@b62ddb3c6d9de7dcb1cf0f863ef807e04838e938ee73f617c5c053784debb09e
Security Audit — socket — write-workflow