sdd-setup
Audited by Socket on Sep 24, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS: the skill’s main behavior is coherent with repository setup for an issue-driven GitHub workflow, and its GitHub/file operations are proportionate. The key risk is transitive trust: it asks the agent to install `mattpocock/skills` via a third-party `skills` CLI/plugin path, expanding the trust boundary beyond this skill. No credential harvesting, covert exfiltration, pre-execution directives, or unrelated data flows are present.
No explicit malware is evident in this workflow, but it combines untrusted pull-request content with a secret-bearing AI action, write permissions, OIDC capability, and an unpinned third-party plugin. Restrict execution to trusted contributors or use a safer event/approval design, minimize permissions, avoid exposing secrets to untrusted PRs, and pin actions and plugin dependencies to immutable revisions.