github-sandbox-file-downloader
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s main behavior matches its description, but it asks users to trust and fork a third-party repo unrelated to the named publisher, enable write-capable GitHub Actions, and ingest arbitrary remote files into the repository. This looks more like a risky automation pattern than confirmed malware.
Confidence: 87%Severity: 69%
Audit Metadata