user-story-implementer

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s repo-automation purpose broadly matches its capabilities, and it uses official GitHub tooling rather than suspicious third-party infrastructure. However, it gives an AI agent autonomous real-world write actions on a repository and processes untrusted GitHub content with write/exec permissions, which is a meaningful security risk even without clear malicious intent.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
May 15, 2026, 05:45 AM
Package URL
pkg:socket/skills-sh/eho%2Fagent-skills%2Fuser-story-implementer%2F@8e4680240b05548355601d59ba1b290ac0b19e92
Security Audit — socket — user-story-implementer