overnight-pipeline
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the main external tooling appears official, but its footprint is still high risk because it enables unattended code execution and autonomous repo actions including push/PR/merge. The biggest concern is not credential theft or hidden exfiltration; it is disproportionate autonomy combined with write/exec access and iterative processing of untrusted repo/CI content.
Confidence: 85%Severity: 81%
Audit Metadata