loop-workflows

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned as a repo issue-to-PR workflow, with no obvious malware, installer abuse, or credential harvesting in the provided file. However, it is high-risk operationally because it lets an agent autonomously act on untrusted issue content and publish project changes/PR artifacts without per-action confirmation, while delegating concrete tracker command trust to separate repo policy files not reviewed here.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Jul 28, 2026, 03:14 PM
Package URL
pkg:socket/skills-sh/LayishSieger%2Fagent-workflows%2Floop-workflows%2F@de5a1cc3c230ef4e4fbd153f10cb11de2c1a2d72a5c50ef92f77ff8fde9a2795
Security Audit — socket — loop-workflows