github-project-management

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment is largely coherent with its stated purpose of swarm-coordinated GitHub project management. It relies on standard tooling and does not reveal obvious malicious behavior. The primary caution is to replace placeholder external webhook endpoints with trusted, authenticated targets and enforce strict access control for swarm operations. Overall risk is moderate due to external dependencies and real-time endpoints, but the content itself does not indicate malware or credential harvesting.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:19 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fgithub-project-management%2F@57dc94feb1203b67d9c8b8025930c82476bb0497