catalyst-github
Warn
Audited by Socket on Sep 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and read-only GitHub workflow are coherent, but it routes all access through an external Catalyst CLI whose public provenance could not be verified from the provided evidence. That makes this primarily a supply-chain and trust-boundary concern rather than confirmed malicious behavior.
Confidence: 84%Severity: 72%
Audit Metadata