github-repo-init
Warn
Audited by Socket on Mar 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The intended GitHub automation behavior is coherent and mostly proportionate, and official tools like gh/git/jq are appropriate. But the advertised install method is a high-risk remote source-and-execute pattern from an unrelated, unverifiable domain (example.com), which is inconsistent with a trustworthy distribution path for this skill. Without the actual script or a verifiable same-org release source, the install trust issue dominates the assessment.
Confidence: 91%Severity: 82%
Audit Metadata