ci

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/ci.mjs

The code appears to be a legitimate GitHub Actions monitoring script. It does not show clear malware indicators or unauthorized data collection. However, it has a meaningful command-injection risk because user-controlled and repository-derived values are interpolated into `execSync` shell commands. Safer argument-array APIs or strict validation should be used, especially for branch names, run IDs, and repository names.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 02:09 PM
Package URL
pkg:socket/skills-sh/google-gemini%2Fgemini-cli%2Fci%2F@3d465fd6b50ff81c444c82772c209d6a83f4514d764ae70b7c8a3e4b7b346912
Security Audit — socket — ci