github-agentic-workflows
Fail
Audited by Socket on Mar 4, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The code fragment is a coherent design/documentation artifact describing how to build and secure GitHub Agentic Workflows using MCP tooling and safe-output patterns. There are no embedded secrets, no direct exfiltration logic, and no executable payloads within the fragment. The content is consistent with a guidance/blueprint at design time; if implemented strictly as documented, it should not introduce malicious behavior. However, the breadth and complexity imply potential operational risk if misused in an automated agent without strict boundaries and proper validation. Overall risk is low in terms of malware but moderate in terms of operational risk if deployed without rigorous controls.
Confidence: 95%Severity: 90%
Audit Metadata