Workflow Automation Builder

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with workflow automation, but its actual footprint is somewhat oversized and trust-poor for a template skill. The biggest issues are the unverified raw GitHub workflow download, mutable third-party GitHub Actions, and forwarding of sensitive deployment/webhook tokens to external actions. This looks more like risky CI/CD automation guidance than confirmed malware.

Confidence: 85%Severity: 63%
Audit Metadata
Analyzed At
Apr 9, 2026, 05:35 PM
Package URL
pkg:socket/skills-sh/chunkytortoise%2Fenterprisehub%2Fworkflow-automation-builder%2F@d932e86cf5d088c6b9b6dd748b7d07742221b14d