github-actions-script-injection

Fail

Audited by Socket on Sep 22, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS/HIGH-RISK skill. While framed as a GitHub Actions security audit aid, it materially equips the agent to perform offensive exploitation, secret exfiltration, stealthy validation, and escalation against CI environments. The main risk is not mere workflow analysis but instructions to weaponize findings and route stolen data to attacker-controlled endpoints.

Confidence: 95%Severity: 92%
Audit Metadata
Analyzed At
Sep 22, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/securityfortech%2Fhacking-skills%2Fgithub-actions-script-injection%2F@bb9fdc04dfb82538bf04cca40d537f045a9a23268010cb30feca4de0e3e832ca
Security Audit — socket — github-actions-script-injection