work-on-issues

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core GitHub/GitLab automation is coherent, but the skill is high-risk because it combines untrusted external content, code-writing/execution, autonomous merge/close actions, and `.env` file propagation. Official tracker CLIs reduce supply-chain concern, yet the overall workflow grants broader and riskier powers than a simple issue-processing skill needs.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Aug 11, 2026, 01:23 AM
Package URL
pkg:socket/skills-sh/utarn%2Fengineer-skills%2Fwork-on-issues%2F@dac38df971679b8058665d2f7776e8e3f3afe2f02ff353425c94d728032e884d
Security Audit — socket — work-on-issues