gh-image
Warn
Audited by Socket on Jul 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is coherent, and data appears intended for GitHub, but it installs unpinned third-party extension code from a personal repo and forwards a full GitHub session credential to that code. The access requested is disproportionate to image upload, making this a high security-risk skill even without confirmed malicious behavior.
Confidence: 89%Severity: 82%
Audit Metadata