bug-review

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
.github/workflows/bug-review-resolve.yml

The workflow is intended to track bug-review resolutions and update repository data after merged pull requests. It contains no evident malware in the provided YAML, but it executes repository-controlled scripts with GH_TOKEN and contents: write permission, then pushes their modifications. This is a significant supply-chain risk if those scripts or checked-in files can be altered by an attacker. Review and pin the scripts, restrict the token permissions where possible, quote shell expansions, and consider preventing automatic pushes from untrusted repository content.

Confidence: 97%Severity: 68%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:50 AM
Package URL
pkg:socket/skills-sh/pproenca%2Fdot-skills%2Fbug-review%2F@a6fc27125ff8478fb5c1d0a746c0091f9e7889ac49696272736deafd42f5965e
Security Audit — socket — bug-review