github-repo-management
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is largely aligned with GitHub repo administration and uses official GitHub endpoints, so it does not look malicious. However, it instructs the agent to read raw local credential stores and potentially sensitive files like SSH keys, which is more invasive than necessary for a repository-management skill and raises medium security risk despite coherent data flows.
Confidence: 91%Severity: 52%
Audit Metadata