claude-code-action

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (guiding Claude Code Action workflow configuration) is coherent with its capabilities. It relies on standard, trusted sources (official GitHub Action, GitHub Secrets, documented Claude authentication methods) and keeps credentials within the expected CI/CD boundaries. Data flows are typical for a CI integration and do not indicate malicious exfiltration or dubious third-party intermediaries. Overall risk is low to moderate (suspicious only for secret-handling exposure if misconfigured) and proportional to its described use case.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 05:20 PM
Package URL
pkg:socket/skills-sh/codyswanngt%2Flisa%2Fclaude-code-action%2F@998479e6f6d44f2448b9832b8de855713fd6975a