github-actions-expert

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] The compiled assessment indicates a benign, purpose-aligned GitHub Actions automation helper with low malicious risk but with notable considerations around external data sources and template security. The best-fitting report is Report 2, which provides a complete workflow lifecycle. An improved synthesis emphasizes secret handling, explicit permission minimization, and provenance verification for version data to reduce configuration risk. LLM verification: No direct malicious code is present in the provided skill instruction file. The document's capabilities align with its stated purpose (detect repo type, generate/improve GitHub Actions workflows). Main risks are operational: automated creation and pushing of workflows can introduce supply-chain risk if templates include inappropriate permissions or third-party actions, and reliance on external documentation tools (Context7/WebSearch) may route information through third parties. Review generated

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:10 PM
Package URL
pkg:socket/skills-sh/testacode%2Fllm-toolkit%2Fgithub-actions-expert%2F@f5f8ea435f230e18d939a59df9e1efe46d103fe4