supply-chain-gate
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed to improve repository security by providing structured processes for triaging dependency alerts and enforcing supply chain policies.- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill follows security best practices by explicitly instructing users not to commit API tokens and to use GitHub Actions secrets for the
SOCKET_SECURITY_API_KEYinreferences/socket-github-actions.md.- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external security alerts (Socket PR comments and dashboard). This attack surface is mitigated by instructions inreferences/alert-triage.mdthat mandate mapping all findings against a localpolicy-allowlist.mdandSECURITY.md, which serve as boundary markers for decision-making. The ingestion points are external PR comments and CI logs; capabilities include running audit commands such asnpm audit.- [EXTERNAL_DOWNLOADS]: References to external resources inreferences/socket-github-actions.mdpoint to Socket.dev, which is a well-known security service. These references are informative and facilitate the intended security purpose of the skill.
Audit Metadata