skillopt

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
.github/workflows/droid.yml

No direct malware is evidenced in this workflow YAML itself; however, it conditionally executes a pinned third-party action while supplying a sensitive API key and granting write permissions to issues and pull requests. This is a notable supply-chain risk because the external action’s behavior and its handling/exfiltration potential for the secret cannot be determined from this snippet. Review the referenced action’s implementation at the pinned commit and verify it does not exfiltrate secrets or misuse write permissions.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 11:30 AM
Package URL
pkg:socket/skills-sh/magnus919%2Fhermes-SkillOpt%2Fskillopt%2F@17bf523c162ec4ce95086feea2b71b1cd32374fa
Security Audit — socket — skillopt