repo-health
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities are coherent with a local repository health audit and its data flows stay local or go directly to GitHub through `gh`, with no credential harvesting or unrelated exfiltration. The main concern is install trust: users are instructed to load a third-party skill directly from a mutable personal GitHub repository, which creates medium supply-chain and transitive-trust risk even though the skill content itself appears proportionate and largely read-only by default.
Confidence: 91%Severity: 56%
Audit Metadata