check
Warn
Audited by Socket on May 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities broadly fit a maintainer/review workflow and its external tooling is official, so this is not malware-like or a credential-harvesting pattern. However, it grants an AI agent substantial write/exec and public-action authority over code, releases, and GitHub state, and it ingests untrusted repo/issue/PR content while doing so; that makes it a medium-high operational risk skill rather than a benign read-only reviewer.
Confidence: 86%Severity: 66%
Audit Metadata