sandcastle
Warn
Audited by Socket on Aug 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill's core behavior is broadly consistent with its stated purpose, but it is high risk because it enables unattended code changes and public GitHub actions while forwarding CLAUDE and GitHub tokens into third-party orchestration tooling and sandboxed agent workflows. This looks more suspicious than benign from a security perspective due to autonomy and credential exposure, though the provided content does not show clear malware, exfiltration, or deceptive behavior.
Confidence: 82%Severity: 78%
Audit Metadata