github-workflow-automation

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s GitHub automation purpose is coherent, but its footprint is high-risk due to mutable `npx` installs, prerelease tooling, and broad autonomous write/deploy actions. No direct malware or overt credential theft is shown, yet the combination of third-party CLI execution, untrusted content processing, and public GitHub side effects makes this unsafe to grant broad unattended use.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Aug 21, 2026, 05:05 AM
Package URL
pkg:socket/skills-sh/i-onlabs%2Fclaude-code-skills%2Fgithub-workflow-automation%2F@69688e0fad281e1452bc7b230b68f1537b14fd46d4240d185e745bed9e12dbb9
Security Audit — socket — github-workflow-automation