depot-github-actions

Warn

Audited by Socket on Aug 3, 2026

1 alert found:

Security
SecurityMEDIUM
evals/fixtures/unsafe-pull-request-target.yml

This workflow is structurally high-risk: it uses pull_request_target and then checks out and executes a script from the untrusted PR head commit (./from-pull-request.sh). This combination commonly enables arbitrary command execution in a higher-trust context, potentially exposing the GitHub token/secrets depending on repository permission settings. The exact maliciousness cannot be confirmed without reviewing from-pull-request.sh, but the supply-chain security risk is elevated based on the orchestration pattern.

Confidence: 74%Severity: 85%
Audit Metadata
Analyzed At
Aug 3, 2026, 01:06 AM
Package URL
pkg:socket/skills-sh/leonardoacosta%2Fskills%2Fdepot-github-actions%2F@e473c854db89bd1ad7977fe1fdfa40c5490aefae73a76c27b60d62c2661c7875
Security Audit — socket — depot-github-actions