repo-manager-reference
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated repo-management purpose is plausible, but the skill routes all GitHub access through an opaque local helper whose provenance is not provided. Broad write/destructive capabilities and credential centralization are proportionate to repo administration in general, yet risky for a reference-only skill because users cannot verify what the helper does with PATs and repository data.
Confidence: 82%Severity: 74%
Audit Metadata