self-healing-ci

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s behavior fits its CI self-healing purpose and its data flows stay within GitHub/repository scope, so there is no strong sign of credential theft or hidden exfiltration. Risk comes from installing a third-party skill from a personal repo, transitive skill loading, unpinned dependency/install paths, and autonomous CI write actions.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 11:38 PM
Package URL
pkg:socket/skills-sh/pskoett%2Fpskoett-ai-skills%2Fself-healing-ci%2F@84621b082e3ae922ec9160bfc9e34a6567418017a45f1fc968f6d5d6e68c2997
Security Audit — socket — self-healing-ci