github-image-upload

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it asks the agent to use a personal third-party GitHub CLI extension and potentially forward a full-account GitHub session cookie/token to that external code. Data flows stay within GitHub, and the prompt-injection mitigations are thoughtful, but the credential-forwarding plus non-registry extension dependency make the overall security risk high.

Confidence: 92%Severity: 84%
Audit Metadata
Analyzed At
Sep 9, 2026, 08:27 AM
Package URL
pkg:socket/skills-sh/drogers0%2Fgh-image%2Fgithub-image-upload%2F@452eb388cbb50db5aaa8890c77d5fe868d0678af5f47f18030ac6f0c26fe1cf8
Security Audit — socket — github-image-upload