setup-syn54x-skills
Audited by Socket on Sep 25, 2026
2 alerts found:
SecurityAnomalyNo direct malware or data theft is visible in this workflow. The primary risk is that untrusted issue content and an unpinned third-party plugin may influence a privileged AI agent with repository write access. Pin dependencies to immutable revisions, minimize permissions, and review or constrain issue-derived instructions and agent changes.
No explicit malware is present in the workflow configuration. It creates a supply-chain and PR trust risk by running a mutable third-party action and remotely sourced plugin with an API secret and broad write permissions on matching PRs. Pin the action and plugin to verified immutable revisions, minimize permissions, and restrict secret-bearing execution to trusted PRs.