setup
Warn
Audited by Socket on May 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's core setup purpose is plausible, but it plants high-impact CI workflows that execute unpinned external code, forward multiple secrets to MCP tooling, and let an agent process untrusted content with write/exec/push capabilities. The behavior is not clearly malicious, yet the install trust and data-flow footprint are materially riskier than a normal setup helper.
Confidence: 83%Severity: 78%
Audit Metadata