github-ci-fix

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is broadly aligned with GitHub CI/PR repair and uses expected GitHub tooling, so it does not look malicious. The main risk is operational: it combines untrusted GitHub content ingestion with autonomous code changes, pushes, and PR actions, and it also chains into another skill not shown here. Overall classification: SUSPICIOUS due to autonomy and indirect prompt-injection exposure, not due to credential theft or overt exfiltration.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 09:46 AM
Package URL
pkg:socket/skills-sh/ingpoc%2FSKILLS%2Fgithub-ci-fix%2F@8cd7f1507ce7c30a022d4910084ce2821152e39aa216ca72bce7c0e94332a2c7
Security Audit — socket — github-ci-fix