jabraf-workflows-npm-publish

Fail

Audited by Snyk on Jun 20, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). These are links to a third‑party GitHub repository and a reusable GitHub Actions workflow — not direct binaries, but reusing unknown workflows can be risky because they run code in your CI and may access secrets or perform malicious actions.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 20, 2026, 11:17 AM
Issues
1
Security Audit — snyk — jabraf-workflows-npm-publish