workflow-multi-cli-plan

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated planning purpose broadly matches the workflow, but the footprint is wider than a simple planner. The main concerns are transitive trust in other skills/agents, ingestion of untrusted project/search content into planning prompts, and an auto-approval path that hands off execution with limited review. No direct credential theft or clear exfiltration is shown, so this is not confirmed malware, but it is a medium-high risk orchestration skill.

Confidence: 85%Severity: 69%
Audit Metadata
Analyzed At
Apr 6, 2026, 11:09 AM
Package URL
pkg:socket/skills-sh/catlog22%2FClaude-Code-Workflow%2Fworkflow-multi-cli-plan%2F@fe3a8c1f99c7c1ba29d20bd46a8eb0f1fe2af609