cli-anything-dify-workflow

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent with local workflow-file manipulation, but install trust is weaker than expected because the skill requires direct GitHub installs, including a mutable branch from an unrelated third-party repo. No evidence of credential harvesting or exfiltration is present, so this looks like a supply-chain risk and trust issue rather than malicious behavior.

Confidence: 84%Severity: 54%
Audit Metadata
Analyzed At
Apr 18, 2026, 12:03 PM
Package URL
pkg:socket/skills-sh/HKUDS%2FCLI-Anything%2Fcli-anything-dify-workflow%2F@c31bb17a25a73a4f25315dd601b6d905683a4c53
Security Audit — socket — cli-anything-dify-workflow