skillopt
Warn
Audited by Socket on Aug 11, 2026
1 alert found:
AnomalyAnomaly.github/workflows/droid.yml
LOWAnomalyLOW
.github/workflows/droid.yml
No explicit malicious logic is visible in the workflow YAML itself, but it creates a notable supply-chain risk by executing a third-party pinned action and directly passing a sensitive API key into it, while also granting the ability to write to issues and pull requests. Without inspecting the third-party action’s implementation and its network/credential handling behavior, credential exfiltration or unauthorized repository/issue modifications cannot be ruled out.
Confidence: 62%Severity: 62%
Audit Metadata