report-writing
Warn
Audited by Socket on May 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the main reporting functionality is coherent and mostly documentation-like, but the recommendation to install and invoke a third-party GitHub skill introduces disproportionate transitive trust risk. No direct credential theft or exfiltration is shown, but the unpinned GitHub skill install materially raises security risk beyond the stated purpose.
Confidence: 90%Severity: 74%
Audit Metadata