rjv-github-image-upload

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core purpose is coherent, but the skill’s footprint is riskier than a normal GitHub helper because it installs third-party code and forwards a full-account GitHub session credential to it. Data flows go to GitHub rather than an obvious attacker domain, so this is not confirmed malware, but the credential-forwarding and non-official extension install make it high security risk.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Jul 8, 2026, 07:02 AM
Package URL
pkg:socket/skills-sh/rjvim%2Fai-skills%2Frjv-github-image-upload%2F@7ed29c4c37ecc1a66234a16b7964e02639e4c7f54e270d2a1a6265b24e4c95fd
Security Audit — socket — rjv-github-image-upload