gpc-ci-integration

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose—CI/CD integration for GPC workflows—is coherent with its examples and commands. However, the footprint includes downloading and executing an external script to install a binary (unverifiable) in addition to installing an official npm package, creating a non-trivial supply-chain risk. It handles sensitive credentials (GPC_SERVICE_ACCOUNT) as environment secrets in CI, which is standard but raises data-flow and logging considerations. Overall, the design is plausibly legitimate for CI automation but is SECURITY-SENSITIVE and would be categorized as SUSPICIOUS to HIGH risk without stronger verifications (code signing, pinned versions, and transparent install provenance).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 01:59 PM
Package URL
pkg:socket/skills-sh/yasserstudio%2Fgpc-skills%2Fgpc-ci-integration%2F@aa8a92a23258f21e5eec5d85e4d48868cae318e4