github-project-management

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core GitHub project-management purpose matches the GitHub CLI and write access requested, but the optional swarm features expand trust to third-party npm tooling (`claude-flow`/`ruv-swarm`) that is not same-org to the publisher and is fetched/executed dynamically. This is not confirmed malware, but it is a medium-risk skill because authenticated GitHub workflows and project data may be handled by external automation packages, with an added concern from the unpinned `@alpha` install path.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Aug 21, 2026, 05:05 AM
Package URL
pkg:socket/skills-sh/i-onlabs%2Fclaude-code-skills%2Fgithub-project-management%2F@4937836606a28157fcd9b883b5884982d3ddccb0bbe4290747215af4b34bfa79
Security Audit — socket — github-project-management