dev-context-engineering

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/fca-compliance-gate.yml

The workflow is a legitimate compliance-gate scaffold and contains no evident malicious behavior or intentional data theft. It has meaningful supply-chain and CI correctness risks: mutable third-party action references, runtime installation of unpinned tools, swallowed dependency-audit failures, and omission of dependency-scan from the blocking summary condition. Pin actions and tools to trusted immutable versions, quote file variables, generalize branch handling, and make dependency findings fail the gate when required.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 09:37 AM
Package URL
pkg:socket/skills-sh/vasilyu1983%2Fai-agents-public%2Fdev-context-engineering%2F@52b55ec3a9bb2364382e90390662b2a766e826d4386af4309ffa46fc9c6ad48d
Security Audit — socket — dev-context-engineering