pr-mining-coordinator

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated PR-mining purpose is plausible, but the skill’s main execution path reads a GitHub token from macOS Keychain and forwards it to an unverified local miner script with unspecified network behavior. That credential-forwarding plus unverifiable dependency provenance makes the footprint disproportionate to a coordination skill and drives high security risk, though the text does not by itself prove confirmed malware.

Confidence: 87%Severity: 86%
Audit Metadata
Analyzed At
Mar 29, 2026, 05:29 PM
Package URL
pkg:socket/skills-sh/notque%2Fclaude-code-toolkit%2Fpr-mining-coordinator%2F@14528dbbb46cbf12bf8eb7899841d6384554d698