find-scene

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
.github/workflows/deploy.yml

No explicit malware is visible in the provided YAML, but it implements a high-risk supply-chain pattern: it downloads and executes an unpinned, unverified remote installer script as root (`curl ... | sudo sh`) on every main-branch push, then uses a secret token to publish to an external registry. If the upstream installer or its hosting is compromised, the workflow provides a straightforward path to tamper with the CI environment and abuse publishing credentials/artifacts.

Confidence: 71%Severity: 80%
Audit Metadata
Analyzed At
Apr 28, 2026, 05:14 PM
Package URL
pkg:socket/skills-sh/uriva%2Ffind-scene-skill%2Ffind-scene%2F@aa53a5a886b2dedf4fc4afbe78b9a40a9dec0d81