workflows-work

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core purpose is legitimate developer workflow automation, but the footprint goes beyond local plan execution by invoking other skills, spawning subagents, uploading screenshots to third-party hosts, and autonomously pushing code and creating PRs. The main concern is transitive trust and external data flow, not confirmed malware.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/udecode%2Fplate%2Fworkflows-work%2F@8313b1fdcaca9501c7e1aadbfc9c6a6f3e660012