workflow-e2e-from-changes

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose fits a testing workflow, but the skill is mostly a thin wrapper around opaque slash commands with mandatory sequential execution. There is no direct credential theft or exfiltration evidence, yet the hidden downstream behavior and possible transitive workflow delegation make the overall trust profile medium risk.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
Mar 21, 2026, 03:52 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fworkflow-e2e-from-changes%2F@df379e9b1d4f320c975a2fb98164a00d7f48c8c4