self-healing-ci
Warn
Audited by Socket on Jun 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s behavior fits its CI self-healing purpose and its data flows stay within GitHub/repository scope, so there is no strong sign of credential theft or hidden exfiltration. Risk comes from installing a third-party skill from a personal repo, transitive skill loading, unpinned dependency/install paths, and autonomous CI write actions.
Confidence: 100%Severity: 60%
Audit Metadata