workflow-composer

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches orchestration, and the same-org GitHub marketplace install path is reasonably consistent with official plugin docs, so this is not confirmed malware. However, the skill is high-leverage: it can launch arbitrary other skills, execute Bash, automate retries/parallel flows, and even install community workflows, creating significant transitive-trust and indirect prompt-injection risk disproportionate to a simple workflow helper.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Apr 6, 2026, 11:50 PM
Package URL
pkg:socket/skills-sh/GLINCKER%2Fclaude-code-marketplace%2Fworkflow-composer%2F@64e30a2922da2825f5ada25d4acb11cfda00cc86
Security Audit — socket — workflow-composer