testing-ci

Warn

Audited by Socket on Mar 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s stated purpose (CI/CD automation with parallel testing, flaky test management, and reporting) is broadly coherent with its capabilities and data flows. There is a moderate security exposure due to documented download-and-execute patterns in integration notes and the use of secrets (GITHUB_TOKEN, CODECOV_TOKEN) that require careful handling. No unverifiable binaries are explicitly required by the skill, but the download-execute pattern in the notes should be avoided or pinned with checksums and trusted sources. Overall, the risk is MEDIUM with notable supply-chain and credential-handling considerations; ensure strict secret management, input validation, and confirm that any external scripts are from verified sources and pinned.

Confidence: 68%Severity: 52%
Audit Metadata
Analyzed At
Mar 7, 2026, 05:46 PM
Package URL
pkg:socket/skills-sh/alphaonedev%2Fopenclaw-graph%2Ftesting-ci%2F@ab58ce6c30ab6e1c307f5c4ba7a5540624dd0909