workflow-lite-execute

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose fits a workflow executor, but its implementation has a serious command-injection path and notable prompt-injection/trust-chain risk. External CLI use is somewhat consistent with purpose, yet the broad Bash/Agent execution and skill handoff make the overall security risk high despite low evidence of intentional malware.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
May 5, 2026, 04:05 AM
Package URL
pkg:socket/skills-sh/catlog22%2Fclaude-code-workflow%2Fworkflow-lite-execute%2F@7d4d7a72e1c7b5bf4f68f8deb53e248eebba42e7