automate-before-manual
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is plausible, but its footprint is overly broad and high-impact. It normalizes reading raw credential files from a shared vault, then using them for GitHub, Azure, SSH, deployment, and browser actions with minimal user approval; the extra instruction to follow another skill further expands trust.
Confidence: 89%Severity: 81%
Audit Metadata