catalyst-github

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and read-only GitHub workflow are coherent, but it routes all access through an external Catalyst CLI whose public provenance could not be verified from the provided evidence. That makes this primarily a supply-chain and trust-boundary concern rather than confirmed malicious behavior.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Sep 22, 2026, 05:52 PM
Package URL
pkg:socket/skills-sh/coalesce-labs%2Fcatalyst-cloud-skills%2Fcatalyst-github%2F@865382a7e05e13341a6258157a7c9c72b8ba7adf620288809a04a6a361589a9a
Security Audit — socket — catalyst-github