workflow-e2e-from-recording
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated E2E-testing purpose is plausible, but the skill mainly acts as a dispatcher into undocumented slash commands and a forced multi-step workflow. No explicit credential theft or exfiltration is visible, yet the hidden command chain and mandatory autonomous execution make the skill medium risk until those commands are documented and bounded.
Confidence: 81%Severity: 58%
Audit Metadata