workflow-migration

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent and the external VM0 tooling appears official, but it is over-privileged for a migration helper because it reads raw local credentials, reproduces them into plaintext .env files, and forwards them into VM0 workflows. The GitHub-based VM0 skill references are same-org and documented, so this is not confirmed malware, but the credential handling and transitive remote-skill loading make it a medium-high risk skill.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
May 19, 2026, 09:41 AM
Package URL
pkg:socket/skills-sh/vm0-ai%2Fvm0-skills%2Fworkflow-migration%2F@986c9460228a26da23e55bfb769a7647177de9cf
Security Audit — socket — workflow-migration