gh-fix

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned for GitHub issue fixing, and its main network/data flows stay within GitHub, but it grants broad autonomous write/merge authority and uses a token-bearing curl upload to an undocumented endpoint. The main concern is high-impact autonomous action scope, not confirmed credential theft or malware.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Sep 11, 2026, 10:55 PM
Package URL
pkg:socket/skills-sh/lsegal%2Fglorp%2Fgh-fix%2F@e7fbaac03397e4ebc26cc642e38e47c0e64f40664b1c190346ccc7192ae51194
Security Audit — socket — gh-fix