epic-dev

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow largely matches its stated Git/GitHub automation purpose, but it introduces a notable supply-chain risk by requiring a third-party gh extension with weak provenance and unnecessary reliance on non-native functionality. No clear credential theft or exfiltration is shown, but the autonomous repo/GitHub actions and transitive install chain make this a high security-risk skill rather than benign.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Jul 20, 2026, 07:19 AM
Package URL
pkg:socket/skills-sh/neuromechanist%2Fresearch-skills%2Fepic-dev%2F@06a72b8a9d25651ee41373461bd315f9706f14e4ab9de2744b2f8811be933dc8
Security Audit — socket — epic-dev