engineering-security-engineer
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated purpose is coherent with its capabilities and it is largely a benign instructional security-engineering guide, but the included CI/CD examples weaken trust by recommending mutable GitHub Actions, especially `trivy-action@master` with documented compromise history. No direct credential harvesting, hidden execution, or disproportionate access appears in the skill itself; the main risk is supply-chain exposure if users copy the workflow examples verbatim.
Confidence: 90%Severity: 64%
Audit Metadata