workflow-review

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches a review workflow, but the skill delegates execution to undocumented slash commands from an unspecified framework and compels autonomous step execution. No direct exfiltration or credential harvesting is shown, yet install/execution trust is incomplete and the opaque command chain makes the skill medium risk.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Mar 21, 2026, 03:52 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fworkflow-review%2F@18b1a59b43d696765c49699a7ccca1852f37aa14