milestone-rush

Warn

Audited by Socket on Aug 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose aligns with repo automation, but its footprint is high-risk because a single invocation grants broad autonomous GitHub actions and delegates to additional internal skills with unclear provenance. There is no clear credential theft or malicious exfiltration, but the combination of autonomous merges/closure, transitive skill trust, and untrusted-content processing makes it a high-risk orchestration skill.

Confidence: 85%Severity: 76%
Audit Metadata
Analyzed At
Aug 22, 2026, 12:00 AM
Package URL
pkg:socket/skills-sh/frostney%2Fknown-good-route%2Fmilestone-rush%2F@1c39990ec7089b09f656b03d27d0d81ed96e7ef030ef39c7bf6c025106df4458
Security Audit — socket — milestone-rush