eo-workflow
Warn
Audited by Socket on Jun 22, 2026
2 alerts found:
Anomalyx2AnomalySKILL.md
LOWAnomalyLOW
SKILL.md
该技能目的与能力大体一致,主要是本地开发流程编排,不像凭证窃取或明显恶意内容。主要风险来自高自动化多代理执行、基于外部生成文本驱动后续动作,以及未披露的 tmux-bridge/eo-* 依赖信任链,因此更适合判为可疑/中风险而非恶意。
Confidence: 82%Severity: 58%
Anomalystart-panes.sh
LOWAnomalyLOW
start-panes.sh
No direct evidence of malware (exfiltration, reverse shells, persistence, credential theft, or obfuscated payloads) is present in this launcher script. However, it materially increases security risk by starting external AI agents with explicit permission/sandbox/approval bypass flags and injecting those commands into tmux panes to execute in the project directory. Treat as security-sensitive workflow automation and ensure claude/codex and tmux-bridge are trusted, hardened, and not subject to prompt/instruction tampering.
Confidence: 62%Severity: 66%
Audit Metadata