loop-it

Warn

Audited by Socket on Aug 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in publisher/data-flow terms but HIGH RISK operationally: the skill’s capabilities align with its GitHub automation purpose and use official tooling, yet it grants an agent broad autonomous control over code changes, PR merges, and issue closure while ingesting untrusted issue content. Main concern is autonomy and prompt-injection exposure, not malware or credential theft.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Aug 9, 2026, 09:16 AM
Package URL
pkg:socket/skills-sh/smallnest%2Fgoal-workflow%2Floop-it%2F@1abd651c338c983196328a9ec7062c7ad4c4dfc2973fdb70e359ba95ea746a73
Security Audit — socket — loop-it