bee-collect

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow is purpose-aligned for issue triage and GitHub issue creation, but the core execution path relies on `gw`/`gf` CLIs whose provenance is not verified in the provided evidence. That makes install/execution trust the main risk; data flows and requested actions otherwise match the stated issue-collection purpose.

Confidence: 81%Severity: 76%
Audit Metadata
Analyzed At
Apr 13, 2026, 06:26 PM
Package URL
pkg:socket/skills-sh/autumnsgrove%2Fgroveengine%2Fbee-collect%2F@ff3771c788c17cbde85742c9521e5c8d8d071e0a