cicd-expert

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
references/security-gates.md

The file contains legitimate CI/CD security guidance and no clear malware or intentional data theft. It does contain materially risky workflow patterns: executing untrusted pull-request code under pull_request_target, using mutable third-party action tags, downloading an unverified latest binary, and granting broad workflow permissions. These issues represent supply-chain and CI compromise risks if copied directly into production. Pin actions and tools to verified immutable versions, avoid executing fork code in privileged workflows, minimize permissions per job, and make policy checks fail closed.

Confidence: 98%Severity: 72%
AnomalyLOW
references/pipeline-examples.md

No clear malicious behavior is present. The fragment is a legitimate set of CI/CD examples, but it contains security-sensitive automation: arbitrary repository code execution, privileged Docker/Kubernetes operations, cross-repository writes, token use in command arguments, and numerous floating image/action tags. These are configuration and supply-chain risks requiring hardening, not evidence of malware in this file.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 14, 2026, 05:55 PM
Package URL
pkg:socket/skills-sh/martinholovsky%2Fclaude-skills-generator%2Fcicd-expert%2F@0984ddafd852b8eafc3825d4106aa2422afc8064b777c3b8edb4d5ec12e2353f
Security Audit — socket — cicd-expert