agent-workflow

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s stated purpose is coherent with productivity-focused workflows and multi-agent orchestration. However, the footprint includes a dangerous download-and-execute pattern (curl | sh) in a Dockerfile and credential exposure practices (environment variables) that are not clearly mitigated. The data-flow model involves multiple external agents and MCP services, raising data governance concerns. Overall, the skill is Suspicious due to supply-chain risk and potential credential exposure, with a notable but not definitive possibility of benign usage in tightly controlled environments.

Confidence: 65%Severity: 65%
Audit Metadata
Analyzed At
Mar 11, 2026, 01:49 PM
Package URL
pkg:socket/skills-sh/akillness%2Foh-my-gods%2Fagent-workflow%2F@994d57f16cbef272ef708720b4d98bd8abaa4345