GitHub Actions CI/CD (AWS ECR + EC2)
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities mostly match its stated CI/CD purpose and its network destinations are expected, so it is not malicious. However, it forwards high-value AWS and SSH credentials into a third-party GitHub Action and relies on long-lived AWS keys rather than OIDC, creating a medium-to-high credential-handling risk for a template skill.
Confidence: 91%Severity: 61%
Audit Metadata