lead
Warn
Audited by Socket on Aug 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-consistent and uses official GitHub tooling, but it grants the agent high-autonomy write/merge powers and mixes untrusted GitHub/repo content with command execution and subagent dispatch. The main concern is operational and prompt-injection risk, not malware or credential theft.
Confidence: 88%Severity: 76%
Audit Metadata