to-tickets
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core behavior is coherent for a ticket-filing skill and its network destinations are official GitHub/GitLab paths, but the instruction to run setup-krit-skills introduces an unverifiable external dependency unrelated to the otherwise straightforward workflow. Without that command, this would be low-to-moderate risk and largely benign.
Confidence: 85%Severity: 72%
Audit Metadata