mj-notes-workflow
Warn
Audited by Socket on Jun 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core note-processing purpose is coherent, and the `getnote` CLI appears to be an official documented dependency, so this is not strong malware evidence. Risk comes from credential use through an external CLI, writable local/remote side effects, untrusted note content feeding later actions, and especially unverified transitive skill delegation (`mj-writer`/`mj-deploy`/`mj-cf-dns`).
Confidence: 100%Severity: 60%
Audit Metadata