github-actions-cache-poisoning
Fail
Audited by Socket on Sep 22, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
MALICIOUS: this skill’s core purpose is offensive exploitation of GitHub Actions caches to achieve code execution in privileged workflows and exfiltrate secrets. Install provenance is mostly official and not the concern; the decisive issue is that the skill operationalizes CI compromise, token extraction, poisoned dependency delivery, and outbound secret theft.
Confidence: 97%Severity: 98%
Audit Metadata