ai-automation-workflows

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill aims to provide automated AI workflows with multiple patterns (batch, sequential, parallel, conditional) and supports both Bash and Python-based automation. However, the footprint includes high-risk download-and-run installation from a remote domain, and explicit transitive skill installation paths, plus external webhook data leakage potential. While the core functionality is plausible for legitimate automation, the combination of curl|bash installer, unverified external binaries, and dynamic skill installation introduces security risks that are not clearly mitigated. Overall assessment: SUSPICIOUS due to supply-chain risk patterns and potential data exposure paths; not clearly benign given the install method and data flows.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fai-automation-workflows%2F@29c956cfe5414be18bc15b5ef440c11a4b0e0686