github-workflow-automation

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN: The skill description is internally consistent with its stated purpose of swarm-powered GitHub workflow automation. It relies on legitimate tooling (gh, npm/npx packages, and documented workflow templates) and does not show irreconcilable or malicious data flows. The main security consideration is the potential for broad access permissions in real use; mitigate with least-privilege and proper secret handling. Overall risk appears low-to-moderate given the context, with no explicit malicious behavior detected in the provided fragment.

Confidence: 78%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:52 AM
Package URL
pkg:socket/skills-sh/frankxai%2Farcanea%2Fgithub-workflow-automation%2F@8e371d72be14a4500e896cb2cf9d9c728b61a72e