oss-contributor-swarm

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its GitHub automation footprint, and the listed external tools appear official, so this is not confirmed malware. However, it grants an AI agent continuous autonomous public write access and processes untrusted GitHub content while editing code and responding to reviews, creating high operational and prompt-injection risk disproportionate to a normal assistive coding skill.

Confidence: 90%Severity: 79%
Audit Metadata
Analyzed At
Mar 21, 2026, 07:20 AM
Package URL
pkg:socket/skills-sh/happycapy-ai%2FHappycapy-skills%2Foss-contributor-swarm%2F@ad7f70b1c3a540b22fef3a0de92bbb6d4f9a7dff