github-agentic-workflows

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN for purpose alignment and data flow integrity: the capabilities, credentials, and official GitHub-based install path fit the stated repository-automation purpose. However, it is still a HIGH-RISK agent skill operationally because it grants autonomous write actions and combines untrusted external content with repo mutation capabilities; the main concern is misuse or prompt-injection-induced actions, not clear malware or credential theft.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
May 18, 2026, 08:29 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fai-agent-skills%2Fgithub-agentic-workflows%2F@362710f459b0a7066783445a03abcc1df97ee058
Security Audit — socket — github-agentic-workflows