ai-automation-workflows

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly aligned with AI workflow automation, but it expands trust through a transitive skill install, relies on a vendor CLI that receives credentials and mediates all model/API traffic, and includes examples that can send workflow data to arbitrary webhooks. This looks more like elevated supply-chain and data-flow risk than confirmed malware.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:31 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fagent-skills-registry%2Fai-automation-workflows%2F@e20946eb6e8f8fa0173f30ad7422039c258c4eb7