shiploop
Warn
Audited by Socket on Jul 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s repo automation purpose broadly matches its GitHub/worker capabilities, but its footprint is high-risk because it enables unattended repository actions after one approval and depends on external tooling with mixed trust. Codex is relatively well-sourced, Hermes uses official but weak remote-install patterns, and the required `autoreview` step has unclear provenance and possible third-party credential/code exposure.
Confidence: 81%Severity: 72%
Audit Metadata