lifecyclemodel-resulting-process-builder
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose and requested inputs are mostly coherent for a lifecycle-model aggregation skill, and the default workflow appears local-first. The main concern is install/execution trust: the skill's critical functionality is delegated to an unpinned external npm CLI (`@latest`) whose provenance was not verified from the provided evidence. Optional API-key use is proportionate, but forwarding credentials and data through an unverified CLI keeps the overall risk in the medium-high range rather than benign.
Confidence: 81%Severity: 72%
Audit Metadata