cicd-intelligent-recovery

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core CI/CD purpose is plausible, and official GitHub CLI usage is consistent, but the skill’s real footprint is too broad: it repeatedly executes an unpinned third-party alpha CLI, routes codebase data and analysis through that service, performs autonomous repository actions, and chains other skills. This is not confirmed malware, but it is a high-risk skill with disproportionate trust and data-flow exposure for a debugging workflow.

Confidence: 90%Severity: 85%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:20 AM
Package URL
pkg:socket/skills-sh/dnyoussef%2Fai-chrome-extension%2Fcicd-intelligent-recovery%2F@723df8e37d176a6ba0f35087a79e313ba31448ee