issue-to-implementation
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: the core GitHub issue-to-PR purpose is coherent, and data flows stay mostly within official GitHub tooling, but the skill is high-impact for an AI agent because it combines untrusted external issue/comment content with local file modification, command execution, and autonomous remote writes (push/PR creation). This is not confirmed malware, but it is a medium-high risk agent skill due to indirect prompt-injection and real-world action potential.
Confidence: 88%Severity: 69%
Audit Metadata