github

Warn

Audited by Socket on May 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. Most capabilities match a normal GitHub operations skill and data flows stay within GitHub, but the optional sub-issue feature requires installing a non-official third-party gh extension that executes with the user’s authenticated GitHub CLI context. That supply-chain and credential-adjacent trust expansion is disproportionate enough to raise the skill above benign, even without direct evidence of exfiltration.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
May 28, 2026, 06:56 AM
Package URL
pkg:socket/skills-sh/i9wa4%2Fdotfiles%2Fgithub%2F@aba6f75d37dc6aedb2bc6c77955b87fbfb755a1a
Security Audit — socket — github