github-actions-cache-poisoning

Fail

Audited by Socket on Sep 22, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

MALICIOUS: this skill’s core purpose is offensive exploitation of GitHub Actions caches to achieve code execution in privileged workflows and exfiltrate secrets. Install provenance is mostly official and not the concern; the decisive issue is that the skill operationalizes CI compromise, token extraction, poisoned dependency delivery, and outbound secret theft.

Confidence: 97%Severity: 98%
Audit Metadata
Analyzed At
Sep 22, 2026, 05:35 PM
Package URL
pkg:socket/skills-sh/securityfortech%2Fhacking-skills%2Fgithub-actions-cache-poisoning%2F@90d28cee5c8b6e5d4e1dff4a1b281f8e4930eed67308a2c93d7ce93c433836d1
Security Audit — socket — github-actions-cache-poisoning