workflow-preflight

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment represents a coherent, multi-language preflight workflow specification for code quality checks. It aligns with its stated purpose, uses legitimate sources and sinks (official registries, standard tooling, and CI patterns), and does not request credentials or perform suspicious data exfiltration within the fragment itself. The primary risk arises from execution-time trust and configuration choices (which tools to run, which configs to trust, and whether to execute potentially networked audits). In absence of embedded secrets or malware indicators, this is best categorized as BENIGN with caution (suspicious-prone if executed with untrusted configurations or to insecure toolchains).

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 12:48 PM
Package URL
pkg:socket/skills-sh/charlesjones-dev%2Fclaude-code-plugins-dev%2Fworkflow-preflight%2F@eede09f69d74b0e7823c166bb62e2968e84cdf43