reproduce-and-fix-issues
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the workflow is coherent for bug reproduction/fix verification, but it relies on externally configured, unspecified automation components and a config-selected skill, which creates significant trust-chain risk. No clear credential harvesting or malicious exfiltration appears, but the combination of unverifiable adapter trust and autonomous Slack/GitHub actions makes this medium-to-high security risk.
Confidence: 84%Severity: 72%
Audit Metadata