github-project-management
Warn
Audited by Socket on Aug 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core GitHub project-management purpose matches the GitHub CLI and write access requested, but the optional swarm features expand trust to third-party npm tooling (`claude-flow`/`ruv-swarm`) that is not same-org to the publisher and is fetched/executed dynamically. This is not confirmed malware, but it is a medium-risk skill because authenticated GitHub workflows and project data may be handled by external automation packages, with an added concern from the unpinned `@alpha` install path.
Confidence: 84%Severity: 62%
Audit Metadata