loop-it
Warn
Audited by Socket on Aug 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN in publisher/data-flow terms but HIGH RISK operationally: the skill’s capabilities align with its GitHub automation purpose and use official tooling, yet it grants an agent broad autonomous control over code changes, PR merges, and issue closure while ingesting untrusted issue content. Main concern is autonomy and prompt-injection exposure, not malware or credential theft.
Confidence: 90%Severity: 78%
Audit Metadata