setup-syn54x-skills

Warn

Audited by Socket on Sep 25, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
workflows/sdd-implement.yml

No direct malware or data theft is visible in this workflow. The primary risk is that untrusted issue content and an unpinned third-party plugin may influence a privileged AI agent with repository write access. Pin dependencies to immutable revisions, minimize permissions, and review or constrain issue-derived instructions and agent changes.

Confidence: 96%Severity: 72%
AnomalyLOW
workflows/sdd-review.yml

No explicit malware is present in the workflow configuration. It creates a supply-chain and PR trust risk by running a mutable third-party action and remotely sourced plugin with an API secret and broad write permissions on matching PRs. Pin the action and plugin to verified immutable revisions, minimize permissions, and restrict secret-bearing execution to trusted PRs.

Confidence: 94%Severity: 67%
Audit Metadata
Analyzed At
Sep 25, 2026, 09:23 PM
Package URL
pkg:socket/skills-sh/syn54x%2Fskills-plus-plus%2Fsetup-syn54x-skills%2F@9b31fd9867ac275168648799e4ed1c4a37115b0739a5c844ff0477d7ecadd056
Security Audit — socket — setup-syn54x-skills