replicate-issue

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent for bug reproduction, and its external tools appear to be official or same-org. The main risk is that it reads untrusted GitHub issue content/comments and then uses that content to drive shell commands, browser automation, and local API actions, which creates an indirect prompt-injection pathway. Process-killing and branch-pulling are impactful but still proportionate to the stated task. No clear credential harvesting or external exfiltration is present.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 11, 2026, 10:41 PM
Package URL
pkg:socket/skills-sh/coleam00%2Farchon%2Freplicate-issue%2F@4d3e9f24c5b03867684b804cd0e2973c360acb7f