milestone-rush
Warn
Audited by Socket on Aug 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose aligns with repo automation, but its footprint is high-risk because a single invocation grants broad autonomous GitHub actions and delegates to additional internal skills with unclear provenance. There is no clear credential theft or malicious exfiltration, but the combination of autonomous merges/closure, transitive skill trust, and untrusted-content processing makes it a high-risk orchestration skill.
Confidence: 85%Severity: 76%
Audit Metadata