gh-bulk-issues

Warn

Audited by Socket on Jul 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches repo automation, but its footprint is high-risk because it parallelizes autonomous code-writing agents, consumes untrusted GitHub content, and performs real GitHub actions (push/PR/comment-fix loops). No clear malicious exfiltration is shown, yet the autonomy and prompt-injection surface make it a high-risk operational skill.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Jul 13, 2026, 12:03 AM
Package URL
pkg:socket/skills-sh/mastra-ai%2Fmastra%2Fgh-bulk-issues%2F@d37fd8e31968743aff14050b463a14f28470033a8507ceaf5e04c04d24c97cf9
Security Audit — socket — gh-bulk-issues