loop-workflows
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-aligned as a repo issue-to-PR workflow, with no obvious malware, installer abuse, or credential harvesting in the provided file. However, it is high-risk operationally because it lets an agent autonomously act on untrusted issue content and publish project changes/PR artifacts without per-action confirmation, while delegating concrete tracker command trust to separate repo policy files not reviewed here.
Confidence: 88%Severity: 74%
Audit Metadata