report-writing

Warn

Audited by Socket on May 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the main reporting functionality is coherent and mostly documentation-like, but the recommendation to install and invoke a third-party GitHub skill introduces disproportionate transitive trust risk. No direct credential theft or exfiltration is shown, but the unpinned GitHub skill install materially raises security risk beyond the stated purpose.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
May 12, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/ByamB4%2Ffind-cve-agent%2Freport-writing%2F@1823b680d9c81a64f571f61412ae2e5fef1c1314
Security Audit — socket — report-writing