workflow-management

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core local workflow-management behavior is benign, but the skill expands its footprint by referencing external agent/skill ecosystems—especially third-party or community-published commands not owned by the same publisher. That transitive trust and autonomy expansion are not fully documented, making the overall skill moderately risky despite no direct credential theft or exfiltration evidence.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 15, 2026, 04:57 AM
Package URL
pkg:socket/skills-sh/vihang-hub%2FIntegrated-SDLC-framework%2Fworkflow-management%2F@0454626db0d86fc2efedf09485d1a38f4a631f41