pack-submit
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN. The skill’s capabilities are internally consistent with its stated purpose of packaging and publishing a skill, and its network/data flows go directly to official GitHub infrastructure. The main risk is high-impact autonomy: it can publicly publish local content and open PRs using ambient GitHub credentials, so security risk is elevated even without signs of malicious intent.
Confidence: 90%Severity: 72%
Audit Metadata