fix-issue

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core workflow is plausibly legitimate for automated issue fixing, but the skill has broad execution authority, can take autonomous repo actions, chains to other skills, and includes a likely unofficial Bitbucket CLI path. This is not confirmed malware, but it exceeds low-risk workflow guidance and should be treated as medium risk automation with supply-chain and trust-boundary concerns.

Confidence: 81%Severity: 62%
Audit Metadata
Analyzed At
May 10, 2026, 12:12 AM
Package URL
pkg:socket/skills-sh/yonatangross%2Forchestkit%2Ffix-issue%2F@a453a3b557a0c7c673199bd15e41484a04c5f1a2