fix-ci

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and GitHub-centric capabilities mostly align, and install trust is low risk because it relies on GitHub's official CLI. The main concern is proportionality and data-flow control: it tells the agent to consume untrusted external check links and then autonomously modify code and push changes in a loop, creating indirect prompt-injection and autonomous action risk even without explicit malicious exfiltration.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 05:00 PM
Package URL
pkg:socket/skills-sh/cursor%2Fplugins%2Ffix-ci%2F@22d79ed45a382df99b95e1135f13ad0170500511