skillopt
Warn
Audited by Socket on Jun 15, 2026
1 alert found:
AnomalyAnomaly.github/workflows/droid.yml
LOWAnomalyLOW
.github/workflows/droid.yml
No direct malware is evidenced in this workflow YAML itself; however, it conditionally executes a pinned third-party action while supplying a sensitive API key and granting write permissions to issues and pull requests. This is a notable supply-chain risk because the external action’s behavior and its handling/exfiltration potential for the secret cannot be determined from this snippet. Review the referenced action’s implementation at the pinned commit and verify it does not exfiltrate secrets or misuse write permissions.
Confidence: 100%Severity: 60%
Audit Metadata