github-cache-hygiene
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, and its toolchain appears to come from verifiable same-org sources, but a key part of its design routes authenticated GitHub CLI traffic through an OpenClaw-hosted Octopool shim instead of GitHub directly. That third-party relay is proportionate to the cache-sharing goal yet materially increases trust and data-flow risk, especially because the skill normalizes using the shim for authorized writes as well as reads.
Confidence: 86%Severity: 61%
Audit Metadata