self-hosted-runner-poisoning
Fail
Audited by Socket on Sep 22, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
MALICIOUS. The skill’s purpose is offensive exploitation of CI runners and its actual footprint matches that: approval bypass, credential theft, exfiltration to attacker-controlled endpoints, persistence installation, and log deletion. It is not a benign documentation or defensive audit skill; it operationalizes compromise and cover-up. The arbitrary pipe-to-shell installer and external exfil endpoints make the risk extreme.
Confidence: 97%Severity: 99%
Audit Metadata