docs-sync
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Purpose and capabilities are mostly aligned for a docs-impact workflow, and install/data-flow trust looks reasonable from the cited official sources. The main risk is operational: it reviews untrusted PR content while retaining shell execution and GitHub write abilities, especially if used with pull_request_target; this makes the skill medium-to-high risk but not malicious.
Confidence: 86%Severity: 69%
Audit Metadata