github-workflow-automation
Warn
Audited by Socket on Jul 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose broadly matches GitHub automation, and its dependencies are mostly official, but its footprint is high-risk because it combines untrusted GitHub content ingestion with AI processing, repository write actions, git command execution, force-push/rebase behavior, and external transmission of code/context to Anthropic. This is not confirmed malware, but it is a powerful automation pattern that needs strong guardrails, least-privilege tokens, approval boundaries, and prompt-injection defenses.
Confidence: 90%Severity: 76%
Audit Metadata