ci-integration

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s CI-facing behavior is broadly consistent with its stated purpose and does not show credential theft or hidden exfiltration, but it does instruct transitive installation of another skill through an unpinned third-party CLI path. Main risk is trust expansion and mild supply-chain exposure, not confirmed malware.

Confidence: 88%Severity: 53%
Audit Metadata
Analyzed At
Mar 25, 2026, 04:23 PM
Package URL
pkg:socket/skills-sh/jwilger%2Fagent-skills%2Fci-integration%2F@8b389f87ed72d6c28faeca6aadc14dd2ea84ce9c