gh-issues

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core GitHub automation behavior matches the stated purpose and uses official GitHub endpoints, so this is not confirmed malware. However, it is high-impact automation: it reads raw local tokens, forwards them into git/curl subprocesses, embeds tokens into remote URLs, can autonomously push code and post PR/review replies, and can send summaries to Telegram. The footprint is broadly coherent but more powerful and invasive than a minimal issue-fetching skill.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Aug 1, 2026, 08:33 AM
Package URL
pkg:socket/skills-sh/LinkupPlatform%2Fopenclaw%2Fgh-issues%2F@a6be9c211f8ef7ed9ad534d67af62f2e5d83132f8d24da1ffd30c16c884e9dcb
Security Audit — socket — gh-issues