GitHub Agentic Workflows Operations

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is a well-structured guidance piece describing how to configure and compose GH-AW workflows with modular imports and safe-outputs. It aligns with the stated automation/CI/CD purpose and demonstrates sound patterns for minimizing direct write actions and controlling data flow. However, it introduces external dependency surfaces (imports from external repos) and MCP server usage that create supply-chain risk if not tightly version-pinned, provenance-verified, and access-controlled. Secrets handling is not directly exposed in code but relies on typical CI secret plumbing, which remains a potential risk if logs or outputs leak. Overall, the document is benign in intent and design, but warrants strict governance around imports, MCP provenance, and secret management to maintain a medium security posture.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 08:07 PM
Package URL
pkg:socket/skills-sh/thomast1906%2Fgithub-copilot-agent-skills%2Fgithub-agentic-workflows-operations%2F@3bfc43c98ffbe9b54c591914ae176d885e37e0a1