gh-issues

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core GitHub automation purpose aligns with GitHub API and git usage, and external endpoints are mostly official GitHub services. However, the skill is high-risk because it reads raw tokens from config files, forwards them into shell/git operations, grants spawned agents autonomous write/push/PR/comment powers, and processes untrusted GitHub content with execution capability. Metadata/install instructions are also internally inconsistent about whether `gh` is required.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
May 15, 2026, 05:24 AM
Package URL
pkg:socket/skills-sh/cryptofedge%2FFEDGE-2.O%2Fgh-issues%2F@47076c8a3e51d0f4078f8881a750ded047cfc313
Security Audit — socket — gh-issues