ship-and-babysit

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN with elevated operational risk. The skill's capabilities are largely aligned with its stated purpose and use official Git/GitHub workflows, but it grants an agent high-autonomy write/push/post behavior and lets untrusted GitHub review content influence code changes, so the main risk is autonomous action and prompt-injection from external comments rather than malware or credential theft.

Confidence: 88%Severity: 63%
Audit Metadata
Analyzed At
May 17, 2026, 11:19 AM
Package URL
pkg:socket/skills-sh/tinyhumansai%2Fopenhuman%2Fship-and-babysit%2F@4ae46efc77fea121f52bae6a22b1fdaacb1ed39e
Security Audit — socket — ship-and-babysit