4-step-program
Warn
Audited by Socket on Apr 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core GitHub-focused behavior is largely aligned with the stated orchestration purpose and uses official GitHub surfaces, but the skill relies on an unverified secondary skill (`code-reviewer`) and enables autonomous GitHub write actions by delegated agents. Main risk is transitive trust plus moderate autonomy, not clear credential theft or malware.
Confidence: 80%Severity: 58%
Audit Metadata