agents-md-sync
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core capability is coherent for a repo documentation skill, and the declared data flow is mostly local and proportionate. The main issue is install/execution trust: it requires executing an unverifiable local shell script from a skill bundle or GitHub checkout with no release verification, which is a high supply-chain risk even without evidence of active exfiltration.
Confidence: 82%Severity: 72%
Audit Metadata