github-issue-driven-dev
Warn
Audited by Socket on May 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s capabilities mostly match its GitHub workflow purpose, and data flows stay on GitHub/local files. Main concern is the unverified optional global `codex-gh-workflow` binary plus the skill’s ability to autonomously create/push GitHub changes; without clearer provenance for that binary, risk is medium rather than benign.
Confidence: 100%Severity: 60%
Audit Metadata