try
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the GitHub CLI/API usage is official and proportionate, but the skill's real function is to grant in-session authority to arbitrary remote SKILL.md content from any repo. The main risk is transitive trust and indirect prompt injection, not malware or credential exfiltration by itself.
Confidence: 91%Severity: 83%
Audit Metadata