github-workflow-automation
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s GitHub automation purpose is coherent, but its footprint is high-risk due to mutable `npx` installs, prerelease tooling, and broad autonomous write/deploy actions. No direct malware or overt credential theft is shown, yet the combination of third-party CLI execution, untrusted content processing, and public GitHub side effects makes this unsafe to grant broad unattended use.
Confidence: 84%Severity: 74%
Audit Metadata