workflow-rig

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are broadly aligned for workload orchestration, but its footprint is high risk: it authorizes durable remote execution, arbitrary shell commands, file editing, and git push using mounted credentials inside a k8s worker. Data flows stay within the claimed joelclaw/Redis/Restate stack rather than an obvious third-party exfiltration endpoint, so this is not confirmed malware. However, the combination of credentialed remote runtime actions and unverifiable local/private CLI trust makes the skill a significant security risk.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Mar 18, 2026, 12:39 PM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Fworkflow-rig%2F@8874643b0c5002e6291bd74521da3d35d0b4033a
Security Audit — socket — workflow-rig