reproduce-and-fix-issues

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow is coherent for bug reproduction/fix verification, but it relies on externally configured, unspecified automation components and a config-selected skill, which creates significant trust-chain risk. No clear credential harvesting or malicious exfiltration appears, but the combination of unverifiable adapter trust and autonomous Slack/GitHub actions makes this medium-to-high security risk.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Aug 21, 2026, 11:23 PM
Package URL
pkg:socket/skills-sh/backnotprop%2Fpstack%2Freproduce-and-fix-issues%2F@6cf116d42a6fa50d098ea93096488976e7514b21b968a0832090f6fc3060ca98
Security Audit — socket — reproduce-and-fix-issues