issue-start
Audited by Socket on Aug 11, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the skill’s repo automation purpose broadly matches its capabilities, and primary data flows go to official GitHub endpoints, but it has a high operational footprint. Autonomous commits/pushes/commenting, base-branch evidence mirroring, untrusted-content ingestion with write/exec ability, and optional use of non-official gh-attach raise material security risk even without clear malicious intent.
No clear evidence of intentional malware/backdoor behavior is present in the fragment. The dominant security risk is the downloader’s pattern: it can fetch attacker-influenced URLs via curl without a strict destination allowlist in the shown code (enabling SSRF-like risk depending on how URL resolution behaves elsewhere). Additionally, SVG is accepted based on a superficial prefix heuristic without sanitization; if SVG is later rendered as active content, this can become a downstream XSS/security issue. Recommended review actions include enforcing URL scheme/host allowlists before curl, limiting download size, and ensuring SVG is sanitized or treated as non-executable/plain content depending on downstream rendering.