github-workflow-automation
Warn
Audited by Socket on Feb 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN: The skill description is internally consistent with its stated purpose of swarm-powered GitHub workflow automation. It relies on legitimate tooling (gh, npm/npx packages, and documented workflow templates) and does not show irreconcilable or malicious data flows. The main security consideration is the potential for broad access permissions in real use; mitigate with least-privilege and proper secret handling. Overall risk appears low-to-moderate given the context, with no explicit malicious behavior detected in the provided fragment.
Confidence: 78%Severity: 75%
Audit Metadata