slo-investigate

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The workflow is largely coherent for SLO investigation and uses proportionate read-only operations with official GitHub endpoints, but the central `gcx` CLI remains publicly unverifiable. That unresolved binary provenance triggers a high supply-chain risk floor, though there is no strong evidence of credential theft, proxying, or malicious intent in the skill itself.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 7, 2026, 10:16 AM
Package URL
pkg:socket/skills-sh/grafana%2Fgcx%2Fslo-investigate%2F@0c55c28f84b67df9095f54f93bed25234efad743