github-workflow-automation
Fail
Audited by Socket on Apr 15, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: the skill is broadly aligned with GitHub workflow automation and uses mostly official tooling, so it is not fundamentally malicious. However, it grants substantial autonomous repository control, sends repository content to a third-party AI API, and processes untrusted GitHub content in workflows that can comment, push, and deploy; combined with non-SHA-pinned actions, this makes the overall risk medium rather than benign.
Confidence: 85%Severity: 61%
Audit Metadata