prd-to-prod-autopilot

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s orchestration scope mostly matches its stated PRD-to-PR purpose, but it grants broad autonomous GitHub actions and relies heavily on transitive sub-skill trust whose provenance and permissions are not provided. No direct malware or credential-stealing behavior is visible, but the combination of autonomous repo actions plus unverified dependent skills makes the overall security posture medium-high risk.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Jul 8, 2026, 06:47 AM
Package URL
pkg:socket/skills-sh/Gil-1%2Fskills%2Fprd-to-prod-autopilot%2F@4009f1eed3f593b57980d1058f55bf8e7605bc6df1bf75643989c2b2570ce504
Security Audit — socket — prd-to-prod-autopilot