github-actions

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/gha-android-composite-action.md

The code implements a legitimate Android build-and-artifact-upload action and contains no evident malware or deliberate data theft. It has a moderate security concern because user-controlled action inputs are interpolated directly into Bash commands and paths, creating potential command-injection risk in workflows that expose those inputs to untrusted pull requests or callers. Restrict `variant` and identifiers to safe allowlisted characters, use environment variables for shell data, validate derived paths, and avoid running this action with untrusted fork input when repository write or secret access is available.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:38 AM
Package URL
pkg:socket/skills-sh/callstackincubator%2Fagent-skills%2Fgithub-actions%2F@bd3231d6081149ce6e6351bd83cbcf3d1f1fa3c623022e5e84f6340c6b1773b5
Security Audit — socket — github-actions