broadcast
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is broadly aligned with cross-repo automation, but its footprint is high-risk because it autonomously discovers repos, executes repo-controlled scripts, pushes branches, and creates PRs without explicit per-action confirmation. Data flows stay mostly within local repos and official GitHub tooling, so this is not confirmed malware, but the capability scope and autonomous external actions make it a high-risk skill.
Confidence: 89%Severity: 78%
Audit Metadata