write-workflow
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill's stated purpose mostly matches its workflow behavior, but its trust model is weak: it requires installing and delegating to external third-party skills from GitHub, creating medium-high supply-chain and transitive trust risk. No direct credential harvesting or exfiltration is present in this host file, but the external dependency chain makes the skill suspicious rather than fully benign.
Confidence: 89%Severity: 72%
Audit Metadata