gh-image

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, and data appears intended for GitHub, but it installs unpinned third-party extension code from a personal repo and forwards a full GitHub session credential to that code. The access requested is disproportionate to image upload, making this a high security-risk skill even without confirmed malicious behavior.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Jul 25, 2026, 02:58 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fgh-image%2F@e068df80719bc3ec9debb9f170302fbc3b1257d1be5c8fa3401cff86de0feb65
Security Audit — socket — gh-image