github-ops
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core GitHub capabilities match the stated purpose and use official GitHub endpoints, so this is not confirmed malware. However, the skill is high-risk because it performs autonomous external actions without user approval, reads a raw token from a local secret file, and injects that token into shell/network operations, including a credential-bearing Git remote URL.
Confidence: 92%Severity: 76%
Audit Metadata