sprint

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the overall purpose is coherent for a GitHub batch-work skill, and data flows mostly match that purpose, but it grants broad autonomous code and PR actions, executes unreviewed repo-local scripts, and exposes a prompt-injection path from GitHub issues into write-capable subagents. No strong evidence of credential theft or malicious exfiltration is present.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
Jul 8, 2026, 04:17 AM
Package URL
pkg:socket/skills-sh/huggingface%2Fopenenv%2Fsprint%2F@037092c79aeda755454fbb3bfc22d57e349f5356d14200920da06c48f53c0f2a
Security Audit — socket — sprint