to-issues

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior matches the stated project-management purpose, and GitHub/local modes are proportionate. Risk is mainly from the Baidu iCafe path depending on an externally named CLI whose official provenance was not established in the evidence; this creates a supply-chain trust gap, but there is no clear credential theft, hidden execution, or malicious data exfiltration.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 01:22 AM
Package URL
pkg:socket/skills-sh/smallnest%2Fgoal-workflow%2Fto-issues%2F@325ecd55c4d81f0b54a1233144821a576ae78d69254d76127106672bb153cb2b
Security Audit — socket — to-issues