bmad-os-findings-triage

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core triage orchestration is coherent, but the skill's footprint is broader than necessary and includes transitive skill execution plus autonomous external actions (commit, push, PR posting, thread resolution). Data flows mainly target official GitHub endpoints, so this is not confirmed malware, but it is a high-risk workflow skill.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Apr 30, 2026, 06:19 PM
Package URL
pkg:socket/skills-sh/bmad-code-org%2Fbmad-utility-skills%2Fbmad-os-findings-triage%2F@811005a9a2e47df8055cef6a63ae988a30c440ec