skill-finish-branch

Warn

Audited by Socket on May 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core branch-management behavior is coherent, and GitHub CLI usage is official and expected. Risk comes from the mandatory third-party Claude Octopus review step, which routes code diffs to external provider tooling and may receive API keys, making the overall footprint broader than a simple finish-branch skill.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 9, 2026, 06:37 AM
Package URL
pkg:socket/skills-sh/nyldn%2Fclaude-octopus%2Fskill-finish-branch%2F@5a29edc4cc578f2bb5f9688c0f3aaf78f9c75bd0