kmp-ci-github-actions
Warn
Audited by Socket on Sep 28, 2026
1 alert found:
AnomalyAnomalyreferences/pr-visual-evidence-workflow.md
LOWAnomalyLOW
references/pr-visual-evidence-workflow.md
No malware or direct data theft is present in the supplied fragment. The workflow has a meaningful credential-exposure risk because it runs a PR-head script after checkout with persisted credentials potentially available. Set persist-credentials: false and review or otherwise constrain the script before using this workflow with write-capable credentials. The referenced script is not supplied, limiting the assessment.
Confidence: 94%Severity: 63%
Audit Metadata