github-actions

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core purpose is coherent, and the CLI install path is official npm-based, but the actual data flow is not direct GitHub API access. Authentication and requests are brokered through Membrane, a third-party intermediary, which increases trust and credential-routing risk beyond a typical GitHub Actions integration. Overall this looks like a legitimate integration skill with medium security risk from proxy-based data flow and unpinned CLI execution, not confirmed malware.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgithub-actions%2F@ab5f43e0aed2a0e1373dd30003b7f8923c35250d