add-model
Warn
Audited by Socket on Jul 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is mostly aligned with its stated purpose, but it grants an agent authority to edit files, run opaque repo scripts with local API credentials, push directly to main, and trigger/monitor GitHub Actions autonomously. Official tooling lowers supply-chain concern, but the combination of credentialed script execution and autonomous remote actions makes the overall risk medium-high rather than benign.
Confidence: 84%Severity: 71%
Audit Metadata