github-automation

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's GitHub-focused capabilities match its stated purpose, and its policy-guard language is coherent. The main concern is data-flow integrity and scope: GitHub OAuth and repository actions are routed through Composio/Rube as a third-party intermediary, and the skill authorizes high-impact operations such as merges, deployments, permissions, and protection changes. This is not confirmed malware, but it carries meaningful security risk due to third-party credential handling and powerful repository control.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fgithub-automation%2F@e999503cb38269cf35fb960cf7e0156da19597e16c8df707129c7a4f5df492fc
Security Audit — socket — github-automation