requirement-workflow

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose mostly matches a development workflow orchestrator, and there is no direct evidence of credential theft or external exfiltration. However, the skill's core execution is delegated to unseen local shell scripts and it explicitly supports injected agents/skills without identifying their source, creating medium transitive-trust and execution risk disproportionate to a simple workflow helper.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Mar 24, 2026, 03:57 PM
Package URL
pkg:socket/skills-sh/learnwy%2Fskills%2Frequirement-workflow%2F@8eaa017b139d357685daa1460a6a7afe793d7f9e