om-auto-implement-spec
Warn
Audited by Socket on Aug 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose matches its capabilities, but it grants an AI agent broad unattended authority to modify code, open/update PRs, comment publicly, and run QA evidence flows. The main risks are autonomous real-world GitHub actions, reliance on other skills for execution, and processing untrusted repo/tracker content while those delegates can write code and act externally.
Confidence: 86%Severity: 72%
Audit Metadata