test-subworkflow

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The visible skill is minimal and purpose-aligned, but it provides almost no auditable behavior of its own and relies entirely on an ambiguously sourced external `synapse` CLI/subworkflow. No credential theft or exfiltration is shown, yet the unverifiable execution dependency makes the skill high-risk to trust.

Confidence: 83%Severity: 78%
Audit Metadata
Analyzed At
Mar 28, 2026, 04:40 AM
Package URL
pkg:socket/skills-sh/s-hiraoku%2Fsynapse-a2a%2Ftest-subworkflow%2F@ed7307cb1fa6f6a3fa180a712fba91c5824911fa