nocobase-workflow-manage

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
references/nodes/script.md

This is documentation for an intentional server-side scripting feature, not malicious code. No direct malware indicators are present. The main security risk is architectural: allowing untrusted scripts to use configured Node.js modules and a node:vm environment may permit filesystem, environment, network, or process access if isolation and authorization are insufficient. Unrestricted execution time also creates a potential resource-exhaustion risk. Treat script authors and WORKFLOW_SCRIPT_MODULES configuration as highly privileged inputs.

Confidence: 97%Severity: 68%
Audit Metadata
Analyzed At
Sep 14, 2026, 06:47 PM
Package URL
pkg:socket/skills-sh/nocobase%2Fskills%2Fnocobase-workflow-manage%2F@3fffcd0bfe27059fe9a419126b305584f67953a3a47f01679ce9315360818dfc
Security Audit — socket — nocobase-workflow-manage