act Local GitHub Actions Runner

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capability matches the stated CI/CD purpose, and upstream act is a real official tool, but the skill’s own installation path is a third-party transitive skill install unrelated to nektos. Risk is driven more by registry trust and local execution of arbitrary workflow steps than by evidence of credential theft or overtly malicious behavior.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Mar 28, 2026, 05:45 PM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fact-local-github-actions-runner%2F@bac5e63a5b0b76e98c5037dd7902f8c9bb03ec50