double-check

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core GitHub review workflow is aligned with the stated purpose, and main network targets are official GitHub endpoints plus a local reporting service. Risk comes from disproportionate autonomy (editing, pushing, commenting, labeling), direct reading of raw tokens from local `.env` files, execution of repo test commands including `npx`, and transitive reliance on other skills for remote environments.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Apr 26, 2026, 02:54 AM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fdouble-check%2F@7ed1e04e416b84a89b7360a7b8b3e23c5beeaebb