skill-feedback
Warn
Audited by Socket on Jul 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The stated purpose and GitHub issue-posting behavior are mostly coherent, and the named path via official gh CLI is proportionate. Risk rises substantially because anonymous mode requires a local unverifiable Python token generator plus a private key file, then forwards the resulting credential to gh; that creates a black-box credential-handling path inconsistent with low-risk feedback collection.
Confidence: 89%Severity: 82%
Audit Metadata