add-bot

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No code-level malware or obfuscated malicious payloads detected. The implementation uses standard tools and GitHub API calls to accomplish its task. The primary security risk is operational: this automation switches active gh authentication and grants push permissions without confirmation, validation, or documented credential handling. In shared or CI environments where seabbs credentials might be available, this could be abused to grant repository write access inadvertently. Recommend adding explicit validation, confirmation prompts, least-privilege guidance, and audit logging before using in automation.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/seabbs%2Fclaude-code-config%2Fadd-bot%2F@5c70eadb660b3370f45a25fad009b9219e3ce433
Security Audit — socket — add-bot