gitea-workflow
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is largely coherent with its stated Gitea workflow purpose and uses the official Tea CLI, but it forwards a Gitea token to unspecified repo-local scripts and enables moderately autonomous repo/PR actions including merges and direct main-branch bookkeeping. No clear credential theft, malware, or third-party exfiltration endpoint is shown, but the unverifiable helper-script data flow keeps risk above benign.
Confidence: 84%Severity: 56%
Audit Metadata