ac-workflow

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

该技能的功能范围与“开发工作流协议”基本一致,未见明确的凭据窃取或数据外传行为,因此不像恶意技能。主要风险在于它强制调用一个来源未说明的 `agent-context` CLI,以及执行本地脚本;这使执行信任不足,整体更适合判为可疑而非恶意。

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 23, 2026, 02:23 PM
Package URL
pkg:socket/skills-sh/cabinet-fe%2Fultra-ui%2Fac-workflow%2F@f00c4406af027a5d03d69e1360406e05583e273a