skillopt

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
.github/workflows/droid.yml

No explicit malicious logic is visible in the workflow YAML itself, but it creates a notable supply-chain risk by executing a third-party pinned action and directly passing a sensitive API key into it, while also granting the ability to write to issues and pull requests. Without inspecting the third-party action’s implementation and its network/credential handling behavior, credential exfiltration or unauthorized repository/issue modifications cannot be ruled out.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Aug 11, 2026, 01:46 AM
Package URL
pkg:socket/skills-sh/magnus919%2Fhermes-skillopt%2Fskillopt%2F@76446813ac70422f7b159909e8175fe451b69d87
Security Audit — socket — skillopt