automate-before-manual

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but its footprint is overly broad and high-impact. It normalizes reading raw credential files from a shared vault, then using them for GitHub, Azure, SSH, deployment, and browser actions with minimal user approval; the extra instruction to follow another skill further expands trust.

Confidence: 89%Severity: 81%
Audit Metadata
Analyzed At
Sep 10, 2026, 06:38 PM
Package URL
pkg:socket/skills-sh/farukzahra%2Fagent-skills%2Fautomate-before-manual%2F@2010495574e563100b269a2c5f88ddeed754539f59b712bd00697c881074dd49
Security Audit — socket — automate-before-manual