gh-attach
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s behavior largely matches its stated GitHub attachment purpose, but it requires installing a third-party CLI extension and forwarding a full GitHub browser session credential to that code. That makes it suspicious rather than malicious: the main concern is supply-chain trust and credential exposure, not obvious exfiltration in the documented flow.
Confidence: 86%Severity: 84%
Audit Metadata