gh-bulk-issues
Warn
Audited by Socket on Jul 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose matches repo automation, but its footprint is high-risk because it parallelizes autonomous code-writing agents, consumes untrusted GitHub content, and performs real GitHub actions (push/PR/comment-fix loops). No clear malicious exfiltration is shown, yet the autonomy and prompt-injection surface make it a high-risk operational skill.
Confidence: 86%Severity: 78%
Audit Metadata