gh-attach

Warn

Audited by Socket on Aug 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s behavior largely matches its stated GitHub attachment purpose, but it requires installing a third-party CLI extension and forwarding a full GitHub browser session credential to that code. That makes it suspicious rather than malicious: the main concern is supply-chain trust and credential exposure, not obvious exfiltration in the documented flow.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Aug 6, 2026, 04:44 AM
Package URL
pkg:socket/skills-sh/github%2Fawesome-copilot%2Fgh-attach%2F@2112de4478f2bc16f48f267582517e40a0aeb6c78de1bc6cd25b7792d594b15f
Security Audit — socket — gh-attach