github-issue-driven-dev

Warn

Audited by Socket on May 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its GitHub workflow purpose, and data flows stay on GitHub/local files. Main concern is the unverified optional global `codex-gh-workflow` binary plus the skill’s ability to autonomously create/push GitHub changes; without clearer provenance for that binary, risk is medium rather than benign.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 25, 2026, 07:30 AM
Package URL
pkg:socket/skills-sh/nanameru%2Fgithub-issue-driven-dev-skill%2Fgithub-issue-driven-dev%2F@edba599a599140f2e18fd3a73e0b839bb5499faa
Security Audit — socket — github-issue-driven-dev