pitfall-experience
Warn
Audited by Socket on May 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the GitHub integration itself is plausible, but the skill is overpowered for a troubleshooting reference tool. It reads a local token file, mandates autonomous issue creation, and most importantly converts untrusted GitHub capsule content into executable remediation guidance, creating a high indirect prompt-injection risk.
Confidence: 84%Severity: 72%
Audit Metadata