github-repo-analyzer

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The main repo-analysis workflow is coherent and mostly benign, and optional Notion sync is proportionate when user-approved. The primary concerns are the unnecessary transitive installation of an acpx plugin to access other agent tools, weak provenance for that plugin, raw credential-file access for Notion, and prompt-injection risk from analyzing arbitrary repositories with powerful external tooling.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 20, 2026, 10:54 AM
Package URL
pkg:socket/skills-sh/4444zyf%2Fskills%2Fgithub-repo-analyzer%2F@ffcb74e1d26bda1c387621bc0fcbb2d8f635aede