om-auto-implement-spec

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose matches its capabilities, but it grants an AI agent broad unattended authority to modify code, open/update PRs, comment publicly, and run QA evidence flows. The main risks are autonomous real-world GitHub actions, reliance on other skills for execution, and processing untrusted repo/tracker content while those delegates can write code and act externally.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Aug 12, 2026, 04:32 AM
Package URL
pkg:socket/skills-sh/open-mercato%2Fskills%2Fom-auto-implement-spec%2F@707c8cd49f605c2379f43ce3c40800fd908be1b045bf9d5be58b405d34c7985a
Security Audit — socket — om-auto-implement-spec