github-workflows

Fail

Audited by Socket on Mar 14, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/gh/scripts/experiment_cleanup.py

This module is an administrative CLI for cleaning experiment-labeled GitHub resources. Based on the provided fragment there are no indicators of credential harvesting, obfuscated payloads, remote shells, or covert exfiltration beyond expected GitHub API usage. The primary risk is operational: it performs destructive actions (closing issues, deleting labels, closing milestones) using the GITHUB_TOKEN and a hardcoded default repo without interactive confirmation. The supplied snippet is syntactically corrupted, so final verification requires the complete, corrected source.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 14, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/gsd-build%2Fgsd-2%2Fgithub-workflows%2F@af4caa50f52df363d5995f4f395cd362c857981e