skill-feedback

Warn

Audited by Socket on Jul 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose and GitHub issue-posting behavior are mostly coherent, and the named path via official gh CLI is proportionate. Risk rises substantially because anonymous mode requires a local unverifiable Python token generator plus a private key file, then forwards the resulting credential to gh; that creates a black-box credential-handling path inconsistent with low-risk feedback collection.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Jul 9, 2026, 07:51 AM
Package URL
pkg:socket/skills-sh/OntoLedgy%2Fol_ai_context_library%2Fskill-feedback%2F@19a540aa6cf7a1905a214f320b929957d5f897d4
Security Audit — socket — skill-feedback