gha-security-review

Fail

Audited by Snyk on Mar 5, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The document contains numerous explicit, actionable exploitation examples (curl|bash payloads, token exfiltration commands, backdoor init()/preinstall hooks, branch/filename expression injection payloads, unpinned-action supply-chain exploits and artifact/cache poisoning) that are dual‑use but provide concrete malicious payloads and step‑by‑step PoC scenarios which could be directly abused for credential theft, RCE, persistence, and supply‑chain compromise.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 5, 2026, 03:27 PM