ci-security-scanning-with-strix
Warn
Audited by Socket on Aug 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is largely coherent with its stated CI security-scanning purpose and uses same-org infrastructure, but it still carries meaningful risk because it installs and executes a remote CLI via curl|bash, forwards sensitive API credentials to that tool/service, and grants an AI agent offensive security-scanning capability. This looks more like a legitimate but high-risk security skill than malware.
Confidence: 90%Severity: 72%
Audit Metadata