exercise-pack
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: the skill’s core behavior fits its stated purpose, and data flows go to expected GitHub services, but it enables autonomous public publishing and release creation without explicit approval at execution time. Main risk is real-world action/autonomy plus moderate supply-chain exposure from a third-party mutable GitHub Action, not credential theft or hidden exfiltration.
Confidence: 89%Severity: 64%
Audit Metadata