gh-issues
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: purpose and GitHub data flows are broadly coherent, but the skill is high-risk because it reads raw credentials from config, forwards them to git/curl, allows autonomous code pushes/PRs/replies, and processes untrusted issue/review content with execution-capable sub-agents. Not confirmed malware, but disproportionate automation and credential handling make it a vulnerable skill.
Confidence: 91%Severity: 78%
Audit Metadata