langchain-core-workflow-b

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill demonstrates a coherent purpose for building LangChain agents with tool calling and streaming capabilities. There are minor security concerns, primarily the use of eval in the calculate tool, which could enable code execution if given untrusted input. Otherwise, no obvious credential exposure, insecure downloads, or data exfiltration patterns are present. Treat the eval usage as the primary risk and consider replacing with a safe math evaluator or sandboxed evaluation. Overall, the footprint is suspiciously scoped but not evidently malicious; warrants cautious review before production.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 01:04 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Flangchain-core-workflow-b%2F@2b1bd3ff6cbe7cf655b036736770df9f3e77bea2