check-ci

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is coherent with its stated purpose: it uses the official gh CLI and git to fetch PR and workflow status and reports results. I found no evidence of download-execute patterns, credential forwarding to third parties, or hidden exfiltration. The primary risks are operational: the skill requires a configured and authenticated gh CLI (so it will run with the operator's GitHub privileges), and any future implementation that interpolates untrusted input into shell command strings could create command injection vulnerabilities. If the skill were changed to run fix commands automatically without explicit user confirmation, that would raise autonomy and safety concerns. Overall this appears functionally appropriate and low-risk if implemented with safe command execution and user approval for any modifying actions.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 03:29 PM
Package URL
pkg:socket/skills-sh/s-hiraoku%2Fsynapse-a2a%2Fcheck-ci%2F@a4b00a9e84849b100f430d09fffa9b71e7fef046