fix-github-issue

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core workflow is coherent for fixing a GitHub issue, but it relies on unprovided external skills and permits autonomous PR creation on CI. No clear credential theft or exfiltration is shown, yet the transitive skill trust and real-world action scope make this a medium-risk agent skill.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
Apr 13, 2026, 02:35 AM
Package URL
pkg:socket/skills-sh/shopify%2Fflash-list%2Ffix-github-issue%2F@ffcfdb30b5000814d11e0c6a10783e6d54f11b27