gha-security-review
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is coherent as a GitHub Actions security-audit playbook and shows no install-chain, credential-harvesting, or exfiltration behavior. However, it equips an AI agent with offensive workflow-exploitation review techniques and instructs analysis of untrusted repository content, creating meaningful security risk despite otherwise proportionate scope.
Confidence: 90%Severity: 74%
Audit Metadata