ops-merge
Warn
Audited by Socket on Oct 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK but not confirmed malware. The skill’s capabilities mostly match its stated PR-automation purpose and it uses official GitHub/Doppler tooling, but it enables high-impact autonomous repo actions and depends on an unreviewable local binary (ops-merge-scan). That unverifiable executable plus admin merges, force-push workflows, and secret retrieval paths make the overall security risk high even without clear evidence of credential exfiltration or malicious intent.
Confidence: 89%Severity: 76%
Audit Metadata