workflow-lite-execute
Warn
Audited by Socket on May 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose fits a workflow executor, but its implementation has a serious command-injection path and notable prompt-injection/trust-chain risk. External CLI use is somewhat consistent with purpose, yet the broad Bash/Agent execution and skill handoff make the overall security risk high despite low evidence of intentional malware.
Confidence: 88%Severity: 78%
Audit Metadata