repo-manager-reference

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated repo-management purpose is plausible, but the skill routes all GitHub access through an opaque local helper whose provenance is not provided. Broad write/destructive capabilities and credential centralization are proportionate to repo administration in general, yet risky for a reference-only skill because users cannot verify what the helper does with PATs and repository data.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Mar 18, 2026, 01:37 PM
Package URL
pkg:socket/skills-sh/l3digital-net%2Fclaude-code-plugins%2Frepo-manager-reference%2F@e535be1c07869096c63b1e1bdcfb9bc0099fe977
Security Audit — socket — repo-manager-reference