github-issue-to-pr
Audited by Socket on Sep 27, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the skill is internally consistent and uses official/service-native endpoints, but it grants an agent autonomous repository write actions and may forward GitHub or build secrets into issue-triggered runs. This is not confirmed malware or covert exfiltration, yet it carries medium-high operational risk because untrusted issue content can drive code changes, pushes, and PR creation.
The code appears to implement GitHub issue-to-pull-request automation rather than covert malware. Its main security concerns are granting an autonomous agent terminal access alongside a GitHub credential, and using an unvalidated automation_id in a local state-file path. The plaintext-settings request and configurable callback are also sensitive trust boundaries. The supplied fragment contains syntax-breaking string truncations, so its exact runtime behavior cannot be confirmed from this text alone.