kmp-ci-github-actions

Warn

Audited by Socket on Sep 28, 2026

1 alert found:

Anomaly
AnomalyLOW
references/pr-visual-evidence-workflow.md

No malware or direct data theft is present in the supplied fragment. The workflow has a meaningful credential-exposure risk because it runs a PR-head script after checkout with persisted credentials potentially available. Set persist-credentials: false and review or otherwise constrain the script before using this workflow with write-capable credentials. The referenced script is not supplied, limiting the assessment.

Confidence: 94%Severity: 63%
Audit Metadata
Analyzed At
Sep 28, 2026, 10:24 AM
Package URL
pkg:socket/skills-sh/ronjunevaldoz%2Fkmp-agent-skills%2Fkmp-ci-github-actions%2F@e8aaa80f14da68f764fb873278a9bc7e5885a182e8a109afb9dd9b9495ae8411
Security Audit — socket — kmp-ci-github-actions