GitHub Actions CI/CD (AWS ECR + EC2)

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated CI/CD purpose and its network destinations are expected, so it is not malicious. However, it forwards high-value AWS and SSH credentials into a third-party GitHub Action and relies on long-lived AWS keys rather than OIDC, creating a medium-to-high credential-handling risk for a template skill.

Confidence: 91%Severity: 61%
Audit Metadata
Analyzed At
Aug 28, 2026, 02:58 AM
Package URL
pkg:socket/skills-sh/yuen30%2Fmy-skills%2Fgithub-actions-cicd-aws-ecr-ec2%2F@b3ef84bac5f89b99ff1ec31e7c5e4efab0044140
Security Audit — socket — GitHub Actions CI/CD (AWS ECR + EC2)