ship-and-babysit
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
BENIGN with elevated operational risk. The skill's capabilities are largely aligned with its stated purpose and use official Git/GitHub workflows, but it grants an agent high-autonomy write/push/post behavior and lets untrusted GitHub review content influence code changes, so the main risk is autonomous action and prompt-injection from external comments rather than malware or credential theft.
Confidence: 88%Severity: 63%
Audit Metadata