workflow-orchestrator

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Anomaly
AnomalyLOW
reference/start-day-protocol.md

The code fragment is a bootstrap orchestration with extensive state reads across git, costs, and context files, plus a potentially dangerous external script source. The top security concern is the optional sourcing of .claude/start-day.sh, which could execute arbitrary commands if tampered with. While there is no explicit evidence of active malware, the design allows a high-impact sink that could compromise confidentiality, integrity, or availability if abused. Overall risk is medium with a single high-impact sink; mitigate by removing or sandboxing the external script source and hardening input validation and error handling.

Confidence: 65%Severity: 60%
Audit Metadata
Analyzed At
Mar 22, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/ScientiaCapital%2Fskills%2Fworkflow-orchestrator%2F@3b60f3467e83ecd878edbdc9ed8c1257aecae19a