groq-ci-integration

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it provides a CI integration setup for Groq, uses GitHub Actions in a conventional manner, and manages secrets through GitHub Secrets without introducing unverified binaries or unintended data exfiltration. The data flow is limited to CI secret usage and standard workflow execution, with proper safeguards (secret masking, guarded tests). A modest security risk exists around secret handling in CI logs if misconfigurations occur, but the provided pattern adheres to expected best practices for CI integrations. Overall, this is BENIGN with low risk; keep monitoring for any accidental secret exposure in logs and ensure separate secrets per environment (prod vs. dev) as noted in the examples.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 12:16 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fgroq-ci-integration%2F@4c75b97b177ce23c420f46548a2bc01835623de3