github-wrapped

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected No signs of intentional malicious behavior in the provided SKILL.md. The skill's capabilities, required inputs, and outputs are consistent with its stated purpose (collect GitHub API responses, build a deterministic dataset, and embed it in a single-file HTML). Primary risks are operational: users must protect raw API JSON (may include sensitive/public-private metadata), must trust and inspect local scripts (scripts/collect_raw.sh, build and embed scripts) before running, and be aware optional CDN assets may cause viewer-side metadata leaks. Recommend auditing the actual scripts referenced (collect_raw.sh, build_dataset_template.py, embed_dataset_into_html_template.py) before running to ensure they do not perform network uploads or other unexpected actions.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:53 AM
Package URL
pkg:socket/skills-sh/acking-you%2Fmyclaude-skills%2Fgithub-wrapped%2F@e14ecdc14dde24218c9bdbc269adf5b8cec50cac