pipeline-validator

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core Azure DevOps capabilities match the stated purpose and tool provenance is legitimate, but the skill is high-risk because it is explicitly autonomous and can repeatedly edit code, push commits, and retrigger pipelines based on untrusted CI log content with no per-action confirmation. Data flows stay mostly within official Microsoft/Git paths, so this looks more like an overpowered automation skill than credential theft or confirmed malware.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Apr 26, 2026, 03:47 PM
Package URL
pkg:socket/skills-sh/rjmurillo%2Fai-agents%2Fpipeline-validator%2F@57b7fbb796b371161f4ae42fa4aff300e537e743