agentic-actions-auditor

Warn

Audited by Socket on Aug 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/vector-a-env-var-intermediary.md

This fragment describes a plausible stealthy GitHub Actions workflow risk: attacker-controlled GitHub event content is assigned into env vars via ${{ github.event.* }} and then referenced by name inside an AI action prompt, causing the AI runtime to ingest untrusted data without obvious ${{ ... }} usage in the prompt field. While the fragment itself is not malicious code, affected workflows using AI tooling that evaluates/reads env vars based on prompt instructions are at elevated risk of prompt injection and any downstream actions the AI can perform.

Confidence: 62%Severity: 63%
Audit Metadata
Analyzed At
Aug 15, 2026, 03:43 AM
Package URL
pkg:socket/skills-sh/waybarrios%2Fopencode-power-pack%2Fagentic-actions-auditor%2F@aa5fe77fc3224d76452b4ebeb74c2d260ff3533cc409f139ada7d0a6278ac87d
Security Audit — socket — agentic-actions-auditor