qe-github-workflow-automation

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill fragment is largely coherent with its stated purpose of swarm-powered GitHub workflow automation and repository orchestration. It relies on legitimate tooling and standard APIs, but its high degree of autonomy (auto-deploy, auto-PR/issue creation, self-healing) and reliance on alpha-stage components introduce governance, supply-chain, and operational risks. Mitigate by enforcing per-action approvals, strict RBAC, input validation, and auditing of generated workflows before enabling autonomous deployment or cross-repo changes.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 06:11 PM
Package URL
pkg:socket/skills-sh/proffesor-for-testing%2Fagentic-qe%2Fqe-github-workflow-automation%2F@b44a40f2ff41799d6f19e537ffa5e3c058251bd1