eb1a-petition

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/rfe-response.md

The fragment is not itself executable malware, but it contains a suspicious external-publication workflow that directs potentially sensitive immigration case data to a hardcoded GitHub repository or form. The approval and anonymization requirements are mitigating controls, but the destination is not an official USCIS endpoint and should be independently validated before use. Review the full file and repository ownership, access controls, issue visibility, and data-handling purpose before deployment.

Confidence: 94%Severity: 63%
Audit Metadata
Analyzed At
Sep 17, 2026, 12:34 AM
Package URL
pkg:socket/skills-sh/tapntell-ai%2Fopenniw%2Feb1a-petition%2F@c2a100792e38dfa3af59a8f83a4d0060de07629de7ce5ecd6e54651ca0fdc83b
Security Audit — socket — eb1a-petition