patch-vulnerabilities
Warn
Audited by Socket on Aug 31, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The overall workflow is coherent for vulnerability management, and network destinations are mostly official service endpoints, so this is not fundamentally incompatible with its stated purpose. However, it reads raw Vanta credentials from a local file through an unverifiable bundled helper script and combines privileged write actions across Vanta, GitHub, and Slack, creating meaningful trust and credential-handling risk.
Confidence: 85%Severity: 64%
Audit Metadata