github-navigator

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the skill fragment shows coherent purpose-to-capability alignment: it uses the official gh CLI to perform GitHub interactions as advertised, with guardrails and explicit authentication guidance. There are no evident attempts to exfiltrate data, execute arbitrary code, or harvest credentials beyond standard CLI Auth flows. The footprint is proportionate to the stated purpose, and data flows are primarily between GitHub and the user through the agent. Security risk is low to moderate, largely contingent on proper handling of gh authentication scopes by the end user.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 08:32 PM
Package URL
pkg:socket/skills-sh/arvindand%2Fagent-skills%2Fgithub-navigator%2F@3c3c82880803efd3bebaf383e4c3384c5d13acf4