session-retrospective

Warn

Audited by Socket on Jul 30, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

全体として目的と機能は概ね整合しており、GitHub Issue作成という用途に沿ったスキルです。ただし、git remote URLからトークンを抽出して`GH_TOKEN`へ渡す非標準な認証処理と、会話内容を外部Issueへ転記するデータ流出リスクがあるため、BENIGNよりはSUSPICIOUS寄りの中程度リスクです。

Confidence: 89%Severity: 56%
AnomalyLOW
SKILL.es.md

This fragment describes an automated conversation retrospective that can create GitHub Issues. The main security concern is the included credential-handling pattern: deriving `GH_TOKEN` from a git remote URL containing an embedded token and exporting it to the environment before calling `gh issue create`. While this may be legitimate for GitHub automation, it is an anomaly in secure design and could increase risk of credential exposure. No definitive malicious payload behavior is visible in the provided fragment, but further review of the referenced scripts is needed.

Confidence: 50%Severity: 50%
Audit Metadata
Analyzed At
Jul 30, 2026, 08:29 PM
Package URL
pkg:socket/skills-sh/minicoohei%2Fai-agent-camp%2Fsession-retrospective%2F@5465f012cd47fb760d1cae2b993e8183731b9d1e8c95b68260424d001a3a7664
Security Audit — socket — session-retrospective