retellai-ci-integration
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalyreferences/ci-configs.md
LOWAnomalyLOW
references/ci-configs.md
No direct malware is evident in the supplied workflows and test fragment. The main security concern is excessive production API-key exposure to npm installation, tests, build, and publish steps, including potentially compromised dependencies or scripts. Restrict the secret to the single integration-test step, use environment-scoped protections, pin actions to immutable SHAs, and strengthen the release process with provenance and controlled publishing.
Confidence: 96%Severity: 56%
Audit Metadata