github-workflow-automation

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The artifact presents a coherent, feature-rich approach to swarm-powered GitHub workflow automation aligned with its stated goals, but introduces supply-chain and operational risk through alpha tooling, broad autonomous capabilities, and extensive external dependencies. Not inherently malicious, but necessitates strong governance: pin versions, enforce least privilege, require per-action approvals, audit logs, and secure secret handling prior to production use.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 07:41 PM
Package URL
pkg:socket/skills-sh/plurigrid%2Fasi%2Fgithub-workflow-automation%2F@8c50c866f0d2aedb4157c3a071016839713dad96