autonomous-workflow

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core behavior matches its stated purpose, but it materially increases risk through autonomous repository/GitHub actions and transitive installation of many companion skills and an optional agent. No clear credential theft or exfiltration is present, so this is better classified as a high-privilege, medium-risk orchestrator rather than malware.

Confidence: 86%Severity: 66%
Audit Metadata
Analyzed At
May 17, 2026, 04:56 AM
Package URL
pkg:socket/skills-sh/mthines%2Fagent-skills%2Fautonomous-workflow%2F@83c5446f833ef4a3cdfc6bb173dee64bd154f887
Security Audit — socket — autonomous-workflow