github-auth

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is legitimate and its network targets are official GitHub services, so it does not look malicious. However, it unnecessarily instructs the agent to read raw credential files and promotes weak secret-handling patterns such as plaintext credential storage and token extraction, creating a medium security risk disproportionate to a simple auth helper.

Confidence: 91%Severity: 58%
Audit Metadata
Analyzed At
May 19, 2026, 07:48 PM
Package URL
pkg:socket/skills-sh/fikriaf%2Fagentos%2Fgithub-auth%2F@f13f80f17a05229df31d1425f8377f32d3865eb4
Security Audit — socket — github-auth