eo-workflow

Warn

Audited by Socket on Jun 22, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

该技能目的与能力大体一致,主要是本地开发流程编排,不像凭证窃取或明显恶意内容。主要风险来自高自动化多代理执行、基于外部生成文本驱动后续动作,以及未披露的 tmux-bridge/eo-* 依赖信任链,因此更适合判为可疑/中风险而非恶意。

Confidence: 82%Severity: 58%
AnomalyLOW
start-panes.sh

No direct evidence of malware (exfiltration, reverse shells, persistence, credential theft, or obfuscated payloads) is present in this launcher script. However, it materially increases security risk by starting external AI agents with explicit permission/sandbox/approval bypass flags and injecting those commands into tmux panes to execute in the project directory. Treat as security-sensitive workflow automation and ensure claude/codex and tmux-bridge are trusted, hardened, and not subject to prompt/instruction tampering.

Confidence: 62%Severity: 66%
Audit Metadata
Analyzed At
Jun 22, 2026, 06:05 PM
Package URL
pkg:socket/skills-sh/SimpleEve%2Feo-skills%2Feo-workflow%2F@b7d1dd6fbf8316d3d7a3b2752ed0cff8c97f16fe8188ff9d8e28174930a79f5e
Security Audit — socket — eo-workflow