gitea-workflow

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated Gitea workflow purpose and uses the official Tea CLI, but it forwards a Gitea token to unspecified repo-local scripts and enables moderately autonomous repo/PR actions including merges and direct main-branch bookkeeping. No clear credential theft, malware, or third-party exfiltration endpoint is shown, but the unverifiable helper-script data flow keeps risk above benign.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Sep 17, 2026, 01:09 PM
Package URL
pkg:socket/skills-sh/jwynia%2Fagent-skills%2Fgitea-workflow%2F@371a66585c2bdf88661bfbf9ad1e078b1fd6df81df65412f06bc74f3a5091bce
Security Audit — socket — gitea-workflow