github-issue-to-pr

Warn

Audited by Socket on Sep 27, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent and uses official/service-native endpoints, but it grants an agent autonomous repository write actions and may forward GitHub or build secrets into issue-triggered runs. This is not confirmed malware or covert exfiltration, yet it carries medium-high operational risk because untrusted issue content can drive code changes, pushes, and PR creation.

Confidence: 91%Severity: 72%
AnomalyLOW
scripts/main.py

The code appears to implement GitHub issue-to-pull-request automation rather than covert malware. Its main security concerns are granting an autonomous agent terminal access alongside a GitHub credential, and using an unvalidated automation_id in a local state-file path. The plaintext-settings request and configurable callback are also sensitive trust boundaries. The supplied fragment contains syntax-breaking string truncations, so its exact runtime behavior cannot be confirmed from this text alone.

Confidence: 91%Severity: 67%
Audit Metadata
Analyzed At
Sep 27, 2026, 03:38 PM
Package URL
pkg:socket/skills-sh/openhands%2Fextensions%2Fgithub-issue-to-pr%2F@ca8cb8b05d314f4a51a8cab1a7e10d0ac0338de2a3924e3888076f93c825e64a
Security Audit — socket — github-issue-to-pr