github-workflow-automation

Warn

Audited by Socket on Jul 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches GitHub automation, and its dependencies are mostly official, but its footprint is high-risk because it combines untrusted GitHub content ingestion with AI processing, repository write actions, git command execution, force-push/rebase behavior, and external transmission of code/context to Anthropic. This is not confirmed malware, but it is a powerful automation pattern that needs strong guardrails, least-privilege tokens, approval boundaries, and prompt-injection defenses.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Jul 23, 2026, 01:47 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fgithub-workflow-automation%2F@3585ad0019b95628730a7a51b82b4ef5a302a4147a34d4f7ff0fac97241c942e
Security Audit — socket — github-workflow-automation