github-author-context

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and data flows mostly align with maintainer review work, and GitHub API usage is official. The main issue is required dependence on an unverifiable local `clawtributors` executable plus broad local maintainer-data access and autonomous note-writing, which raises security risk without clear evidence of malicious intent.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Sep 16, 2026, 11:27 PM
Package URL
pkg:socket/skills-sh/steipete%2Fagent-scripts%2Fgithub-author-context%2F@fea4f40eb04c9dbfff443e4170f3cdbbadad91b5b924dbc02662fb486e78263e
Security Audit — socket — github-author-context