ship
Warn
Audited by Socket on Sep 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core git/GitHub workflow fits a shipping skill, but it manually reads a local Forgejo token and sends it to an unspecified API endpoint, which breaks data-flow transparency. Risk is elevated further by direct-to-main, issue-closing, branch-deletion autonomy and delegation to another skill, though there is no evidence of overt malware or a download-execute installer chain.
Confidence: 88%Severity: 72%
Audit Metadata