expo-cicd-workflows

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] BENIGN: The skill’s stated purpose is coherent with its capabilities and data flows. It relies on official resources and standard tooling to generate/validate Expo EAS workflows. No credential handling, covert data flows, or malicious behaviors are evident in the fragment provided.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:22 PM
Package URL
pkg:socket/skills-sh/sovranbitcoin%2Fsovran%2Fexpo-cicd-workflows%2F@3e9753a3ba093b8be385deb28db384d183f1e8b9