github-repo-management

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely aligned with GitHub repo administration and uses official GitHub endpoints, so it does not look malicious. However, it instructs the agent to read raw local credential stores and potentially sensitive files like SSH keys, which is more invasive than necessary for a repository-management skill and raises medium security risk despite coherent data flows.

Confidence: 91%Severity: 52%
Audit Metadata
Analyzed At
Aug 28, 2026, 12:49 PM
Package URL
pkg:socket/skills-sh/tt-a1i%2Fhermes-agent%2Fgithub-repo-management%2F@49c21b769a25931cb0f2239e3ee33adfb08c64185f0401f9faec2fafd04d9ff3
Security Audit — socket — github-repo-management