eval-creator-ci

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior matches a CI eval runner, and GitHub/gh-aw usage is mostly coherent, but the install path relies on transitive third-party skill installation from a personal repo, the extension version is loosely pinned, and the skill enables headless command execution plus automated PR/check actions. This looks proportionate to CI eval automation, not overtly malicious, but the trust chain and autonomous workflow impact raise medium risk.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 24, 2026, 03:31 AM
Package URL
pkg:socket/skills-sh/pskoett%2Fpskoett-ai-skills%2Feval-creator-ci%2F@f9d9bd19b50cd1aeff932c59520970ef60b24b9a