gh-issues

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: purpose and GitHub data flows are broadly coherent, but the skill is high-risk because it reads raw credentials from config, forwards them to git/curl, allows autonomous code pushes/PRs/replies, and processes untrusted issue/review content with execution-capable sub-agents. Not confirmed malware, but disproportionate automation and credential handling make it a vulnerable skill.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Sep 17, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/firecrawl%2Fopenclaw%2Fgh-issues%2F@a6be9c211f8ef7ed9ad534d67af62f2e5d83132f8d24da1ffd30c16c884e9dcb
Security Audit — socket — gh-issues