gh-issues
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core GitHub automation purpose aligns with GitHub API and git usage, and external endpoints are mostly official GitHub services. However, the skill is high-risk because it reads raw tokens from config files, forwards them into shell/git operations, grants spawned agents autonomous write/push/PR/comment powers, and processes untrusted GitHub content with execution capability. Metadata/install instructions are also internally inconsistent about whether `gh` is required.
Confidence: 90%Severity: 83%
Audit Metadata