build-train

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s GitHub automation purpose is coherent, but its footprint is high-risk for an agent skill because it gives headless Claude workers broad repo action capability, feeds them untrusted issue content, and performs admin merges automatically. Install provenance is mostly legitimate, so this is not confirmed malware, but the autonomy and prompt-injection surface make it a high-risk workflow skill.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 22, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fbuild-train%2F@7e167b2255c0d915c916c0f2a56da1cebb233ceb