github-workflow-best-practices

Pass

Audited by Socket on Feb 21, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Feb 21, 2026, 03:26 PM
Package URL
pkg:socket/skills-sh/squirrelsoft-dev%2Fagency%2Fgithub-workflow-best-practices%2F@68992268c2853f81a35402fa14363a97096ea4aa