github-cache-hygiene

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, and its toolchain appears to come from verifiable same-org sources, but a key part of its design routes authenticated GitHub CLI traffic through an OpenClaw-hosted Octopool shim instead of GitHub directly. That third-party relay is proportionate to the cache-sharing goal yet materially increases trust and data-flow risk, especially because the skill normalizes using the shim for authorized writes as well as reads.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Sep 23, 2026, 10:09 AM
Package URL
pkg:socket/skills-sh/steipete%2Fagent-scripts%2Fgithub-cache-hygiene%2F@eb183571019d8e90c5ccc23bc2bd92854601b0ad243ba031ada7f05837b80809
Security Audit — socket — github-cache-hygiene