abusing-ci-cd-oidc
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is a high-risk offensive security capability for AI agents. Its purpose is explicitly to exploit CI/CD and OIDC weaknesses, and it contains direct credential-harvesting and exfiltration instructions, including an attacker-controlled callback endpoint. There is little supply-chain concern, but the operational abuse, credential access, and exfiltration guidance make the skill dangerous and inconsistent with benign developer-assistance use.
Confidence: 95%Severity: 96%
Audit Metadata