deployment-cicd

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly a benign CI/CD guide, but its Vercel deployment examples route sensitive Vercel tokens through a third-party GitHub Action rather than Vercel's official CLI workflow. That makes the capability slightly inconsistent with least-trust deployment guidance, though there is no strong evidence of malware or exfiltration beyond this credential-forwarding risk.

Confidence: 91%Severity: 58%
Audit Metadata
Analyzed At
Apr 19, 2026, 03:26 AM
Package URL
pkg:socket/skills-sh/4444j99%2Fa-i--skills%2Fdeployment-cicd%2F@2620be753442c54a03aff9534379c886df655881