ops-merge

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches its repo-management behavior, but its operational footprint is very high-risk. The main issues are autonomous code modification/merging across repositories, admin-level merge capability, prompt-injection exposure from untrusted PR/CI content, and especially execution of an unverifiable local helper binary (ops-merge-scan), which forces high security risk even without direct evidence of malware.

Confidence: 86%Severity: 81%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fops-merge%2F@d5fc8b6f5f161ad5e9c44f3e4fc147d95522fdbb
Security Audit — socket — ops-merge