setup-putior-ci

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it automates diagram regeneration and synchronization via CI using legitimate, widely-used tools (GitHub Actions, CRAN/R, and the putior package). Data flow is confined to repository contents and CI runner communications with GitHub; no credential harvesting, exfiltration, or supply-chain attack patterns are evident. Security risk is low to moderate (due to write access and automation), but the controls (guard condition, explicit permissions, and idempotent commits) mitigate common CI-related risks. Overall: BENIGN with standard CI security considerations.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 03:54 AM
Package URL
pkg:socket/skills-sh/pjt222%2Fdevelopment-guides%2Fsetup-putior-ci%2F@0897c55d06783981360919fb380319bbde4de61c