dev-git-workflow

Warn

Audited by Socket on Sep 23, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
assets/ci-cd/gitlab-mr-checks.yml

No clear malicious payload or intentional data theft is present. The configuration has material CI supply-chain and isolation risks: unpinned npm installation and container tags, execution of arbitrary project/dependency scripts, and especially Docker socket exposure to a third-party code-quality image. Security checks are weakened by allow_failure and an unreliable secret-detection command. Pin dependencies and images by lockfile/version or digest, avoid mounting the host Docker socket, use a hardened isolated runner, improve secret scanning, and enforce critical scan failures.

Confidence: 96%Severity: 72%
AnomalyLOW
assets/ci-cd/github-pr-checks.yml

No direct malware or intentional sabotage is evident in this workflow. The main risks are CI supply-chain exposure from mutable third-party action references, execution of pull-request-controlled npm scripts, dynamically installed tooling, and potentially excessive GITHUB_TOKEN permissions. Pin actions to verified commit SHAs, declare minimal permissions, use locked dependencies, and ensure fork PRs cannot access sensitive credentials.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Sep 23, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/vasilyu1983%2Fai-agents-public%2Fdev-git-workflow%2F@5cd99338aa3bb52f512e8e7963a0f02002dc2edbc25d63ac8eec6ca118c9c7a4
Security Audit — socket — dev-git-workflow