gh-issue-autodev

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly aligned with its stated GitHub issue automation purpose and uses normal official tooling, but it grants meaningful autonomous action (commit/push), reads local test credentials for UI login, and chains into other skills. No clear malware or hostile exfiltration path is present, yet the scope is broader and riskier than a simple issue triage helper.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:40 AM
Package URL
pkg:socket/skills-sh/xiaojiongqian%2Fskills-hub%2Fgh-issue-autodev%2F@fff334a6ea1614f5d6b70b8fe44233ac305be1af