guidewire-ci-cd-pipeline

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/API_REFERENCE.md

The document is legitimate CI/CD reference material and contains no clear malware or intentional sabotage. The reusable workflow has security risks: unsafe `eval` of decrypted configuration, direct interpolation of workflow inputs into shell commands and paths, predictable temporary-secret handling, and hand-built JSON. These should be remediated with strict input validation, avoiding `eval`, secure temporary files and cleanup, environment-variable argument passing, and a JSON encoder. The destructive database task should remain blocked from CI through permissions and workflow safeguards.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:50 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Fguidewire-ci-cd-pipeline%2F@dd3fc4736ab0873d1caa7d7c6dbc0cb765774646d5f84096931c06d3898fe521
Security Audit — socket — guidewire-ci-cd-pipeline