pack-submit

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN. The skill’s capabilities are internally consistent with its stated purpose of packaging and publishing a skill, and its network/data flows go directly to official GitHub infrastructure. The main risk is high-impact autonomy: it can publicly publish local content and open PRs using ambient GitHub credentials, so security risk is elevated even without signs of malicious intent.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Aug 20, 2026, 05:30 PM
Package URL
pkg:socket/skills-sh/aeonfun%2Faeon%2Fpack-submit%2F@478e0357254239088d199c47defd8100c074bf35e725bfb3bee49d718568a7cd
Security Audit — socket — pack-submit