security-alerts
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is purpose-aligned and uses official Microsoft/GitHub/npm channels, so it does not look malicious or like credential harvesting. However, it grants an agent broad autonomous authority to modify dependency state, resolve work items, commit code, and invoke another skill for PR creation without per-action approval, making it a medium-risk maintenance automation skill rather than a benign read-only helper.
Confidence: 88%Severity: 62%
Audit Metadata