setup-github

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Suspicious but not malicious. The core behavior matches GitHub setup, and data flows mostly target official services, but the skill relies on third-party skill installation and enables an automated PR review/merge pipeline with meaningful repo impact. Medium risk from transitive trust and autonomous merge behavior, not clear credential theft.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 14, 2026, 09:38 PM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fsetup-github%2F@5181e0253e1b7f66a9b6763b846776cec07c1d5e
Security Audit — socket — setup-github