ss-multi-repo-workflow

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally consistent with a multi-repo orchestration purpose and shows no credential-harvesting or third-party exfiltration behavior, but it enables broad unattended code execution and PR-affecting actions across multiple repositories via nested delegated workflows. Risk is driven by blast radius and delegated execution power, not by malicious data flow.

Confidence: 87%Severity: 63%
Audit Metadata
Analyzed At
Aug 26, 2026, 05:57 PM
Package URL
pkg:socket/skills-sh/lbk-open%2Fsuper-spec%2Fss-multi-repo-workflow%2F@ec911ded1537fcff3ecc93ca6bc10d63de28ebaca2d89febd2c4f399fbcf951e
Security Audit — socket — ss-multi-repo-workflow