learning-aggregator-ci

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's stated purpose mostly matches its behavior—reading `.learnings/` files and posting GitHub reports is coherent for CI aggregation. The main concerns are supply-chain trust from third-party skill installation, transitive trust into other skills/workflows, and autonomous GitHub write actions triggered in CI, especially with `issue_comment` input. No clear credential harvesting or incompatible data exfiltration is shown.

Confidence: 82%Severity: 63%
Audit Metadata
Analyzed At
Apr 24, 2026, 03:31 AM
Package URL
pkg:socket/skills-sh/pskoett%2Fpskoett-ai-skills%2Flearning-aggregator-ci%2F@e559d187e509d5ebf7e34c5527e69376633d1986