github-copilot-cli

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core GitHub Copilot CLI documentation is coherent and mostly benign, using official GitHub install/auth paths. Risk rises because the skill also encourages optional MCP integrations that fetch third-party packages with `npx -y` and pass tokens/DB credentials into them, creating transitive trust and credential-forwarding exposure beyond the core stated purpose.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
May 17, 2026, 06:30 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdevtools-skills%2Fgithub-copilot-cli%2F@81a392ed2223df8ae7b69141a3841236fca47e47
Security Audit — socket — github-copilot-cli