workflow-lite-planex

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The second report provides a more comprehensive analysis of the workflow orchestration spec, including data flows, cross-phase context, and external tool usage. While there is no explicit malware payload, the architecture introduces significant supply-chain and data-exfiltration risk via external agent execution and append-only discovery sharing. Recommend tightening validation gates, auditing external CLI usage, constraining data in context_prev to repository-safe fragments, and adding explicit access-control and data-minimization controls before integration. If the first report lacks coverage on these aspects, adopt the second report as the baseline and implement the suggested control improvements.

Confidence: 98%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 09:02 AM
Package URL
pkg:socket/skills-sh/catlog22%2FClaude-Code-Workflow%2Fworkflow-lite-planex%2F@bf19ff34ba577c7048e1369fd6d1c6f6a8af89eb