oneshot-workflow

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent for a workflow/VCS orchestration purpose, and it does not contain obvious credential theft, exfiltration endpoints, or download-execute installers. The main risks are autonomous repo write actions, opaque MCP-mediated VCS operations, and transitive trust in another skill; these make it medium risk rather than benign.

Confidence: 83%Severity: 57%
Audit Metadata
Analyzed At
May 7, 2026, 04:37 AM
Package URL
pkg:socket/skills-sh/lvlup-sw%2Fexarchos%2Foneshot-workflow%2F@23ce41897a8c02066806330537636a2997239918