exercise-pack

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s core behavior fits its stated purpose, and data flows go to expected GitHub services, but it enables autonomous public publishing and release creation without explicit approval at execution time. Main risk is real-world action/autonomy plus moderate supply-chain exposure from a third-party mutable GitHub Action, not credential theft or hidden exfiltration.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:41 PM
Package URL
pkg:socket/skills-sh/panaversity%2Fagentfactory%2Fexercise-pack%2F@620b6d00399e3edde403cedf9a6eb6da08cfc97f
Security Audit — socket — exercise-pack