django-ticket-triage

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This SKILL.md defines a triage workflow that is internally consistent with its stated purpose: fetching Trac tickets, searching duplicates, checking GitHub PRs via the gh CLI, optionally browsing a local clone of django/. The primary risks are operational (executing local scripts whose source is not included here) and the need for the user to authenticate gh (which uses the user's GitHub credentials). There are no indications in the SKILL.md of credential harvesting, unknown third-party proxies, download-and-execute chains, obfuscation, or direct exfiltration to attacker-controlled domains. Review or audit ./scripts/trac.py and ./scripts/forum.py before executing them in a sensitive environment. Overall assessment: low malicious intent but moderate operational supply-chain risk due to executing external scripts and requiring network access.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 05:32 PM
Package URL
pkg:socket/skills-sh/2ykwang%2Fagent-skills%2Fdjango-ticket-triage%2F@cb052ead9813a7d9dcecbe20a6d5e0cad5a1881d