github-issue-processing

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is mostly aligned with issue triage, and its GitHub CLI data flow is coherent, but it gives an agent authority to autonomously comment on and close issues, processes untrusted issue content with write/action capabilities, and relies partly on repo-local tooling from a personal repository. No clear credential harvesting or covert exfiltration is present, so this is not confirmed malware, but it is a medium-to-high risk operational skill.

Confidence: 87%Severity: 71%
Audit Metadata
Analyzed At
May 11, 2026, 03:08 PM
Package URL
pkg:socket/skills-sh/kongshan001%2Fkanban-framework%2Fgithub-issue-processing%2F@d6c0c765069c0dbec0b80646b4a286d8acfeb856