vs-fix
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s core capabilities broadly match its bug-fixing purpose, and its only explicit external API path is official GitHub CLI usage. However, the combination of fully autonomous repo modification, generic dependency installation, local transitive skill loading, and processing untrusted GitHub issue content while retaining write/exec powers makes the skill medium-high risk.
Confidence: 85%Severity: 64%
Audit Metadata