Summary
workflow-automation v1.0.0 was classified as LOW RISK with a risk score of 7.8. Sigil detected 13 findings across 7 files, covering phases including network exfiltration. Review the findings below before installing this package.
Package description: Use when 用户需要进行工作流自动化:校验允许列表中的工作流、在明确批准后触发其固定 Production Webhook,或读取限定工作流的执行状态与历史;需要 WORKFLOW_AUTOMATION_API_KEY。
v1.0.0
29 August 2026, 21:53 UTC
by Sigil Bot
Risk Score
7.8
Findings
13
Files Scanned
7
Provenance
Findings by Phase
Phase Ordering
Phases are ordered by criticality, with the most dangerous at the top. Click any phase header to expand or collapse its findings. Critical phases are expanded by default.
Badge
Markdown
[](https://sigilsec.ai/scans/22FA6B18-F4BE-4CE0-98C5-F1FB366D7698)HTML
<a href="https://sigilsec.ai/scans/22FA6B18-F4BE-4CE0-98C5-F1FB366D7698"><img src="https://sigilsec.ai/badge/clawhub/workflow-automation" alt="Sigil Scan"></a>Run This Scan Yourself
Scan your own packages
Run Sigil locally to audit any package before it touches your codebase.
Sigil Pro
Cloud scanning, AI investigation, web dashboard, and CI/CD integration. 14-day free trial.
Start free trial →Get threat intelligence and product updates
Security research, new threat signatures, and product updates. No spam.
Other clawhub scans
Believe this result is incorrect? Request a review or see our Terms of Service and Methodology.