gh-release-pipeline
Warn
Audited by Snyk on May 12, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill's workflows invoke third-party GitHub Actions that are fetched and executed at runtime (e.g., uses: cycjimmy/semantic-release-action@v4 — https://github.com/cycjimmy/semantic-release-action), which means remote code from that repo is executed as a required dependency of the release pipeline.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata