issue-create
Audited by Socket on Aug 11, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The core behavior is coherent for an issue-creation workflow, and its expected data flow to GitHub/Jira is proportionate. The main concern is install/execution trust: it references an unverifiable local installer script and transitive skill loading (`migrate-skill-agent.sh`, `gh-setup`) whose provenance and behavior are not provided, so the skill’s reviewed footprint is broader than its stated purpose.
No clear evidence of intentional malware/backdoor behavior is present in the fragment. The dominant security risk is the downloader’s pattern: it can fetch attacker-influenced URLs via curl without a strict destination allowlist in the shown code (enabling SSRF-like risk depending on how URL resolution behaves elsewhere). Additionally, SVG is accepted based on a superficial prefix heuristic without sanitization; if SVG is later rendered as active content, this can become a downstream XSS/security issue. Recommended review actions include enforcing URL scheme/host allowlists before curl, limiting download size, and ensuring SVG is sanitized or treated as non-executable/plain content depending on downstream rendering.