gha-security-review

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is coherent as a GitHub Actions security-audit playbook and shows no install-chain, credential-harvesting, or exfiltration behavior. However, it equips an AI agent with offensive workflow-exploitation review techniques and instructs analysis of untrusted repository content, creating meaningful security risk despite otherwise proportionate scope.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 15, 2026, 07:32 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fgha-security-review%2F@02cd96ef828f28bb8e9ced7d081a4e0d9e6113c1