dotnet-gha-build-test

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is largely coherent with its stated purpose: it documents and demonstrates how to configure a .NET CI workflow in GitHub Actions with multi-version builds, NuGet caching/auth, test result publishing, and coverage reporting. The only notable concern is a documented flag for storing NuGet feed credentials in clear text, which presents a security weakness if misused in real workflows; however, within the context of documentation, it remains a guidance artifact rather than an active credential exposure. Overall, the risk posture is low-to-moderate (benign with documented caveats) and proportional to the CI tooling scope.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 03:45 PM
Package URL
pkg:socket/skills-sh/wshaddix%2Fdotnet-skills%2Fdotnet-gha-build-test%2F@c0b6d841c01fd9fca10f96baa4e51e7623cd2108