workflow-builder

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is coherent with its stated purpose as a workflow-builder guide, but that purpose itself enables broad autonomous action and includes transitive installation of third-party workflows. There is no clear credential theft or malicious exfiltration in this file, yet the combination of autonomous scheduling, silent runs, and skill-to-skill installation makes it a medium-high security risk.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Mar 31, 2026, 11:02 PM
Package URL
pkg:socket/skills-sh/TechNickAI%2Fopenclaw-config%2Fworkflow-builder%2F@5964cd456e4e163d822e14346f85b023883e62c0