epic-dev
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the workflow largely matches its stated Git/GitHub automation purpose, but it introduces a notable supply-chain risk by requiring a third-party gh extension with weak provenance and unnecessary reliance on non-native functionality. No clear credential theft or exfiltration is shown, but the autonomous repo/GitHub actions and transitive install chain make this a high security-risk skill rather than benign.
Confidence: 89%Severity: 74%
Audit Metadata