fix-ci
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN in purpose and data flow, but HIGH operational risk as a skill because it can autonomously modify and push code based on untrusted CI output. The main concern is autonomous repository actions plus prompt-injection exposure from CI logs, not malware or credential theft.
Confidence: 90%Severity: 74%
Audit Metadata