github-auth
Warn
Audited by Socket on May 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s overall purpose is legitimate and its network targets are official GitHub services, so it does not look malicious. However, it unnecessarily instructs the agent to read raw credential files and promotes weak secret-handling patterns such as plaintext credential storage and token extraction, creating a medium security risk disproportionate to a simple auth helper.
Confidence: 91%Severity: 58%
Audit Metadata