dependabot-merger

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose mostly matches its capabilities, but it performs autonomous GitHub write actions and depends on an unspecified jira CLI whose provenance is not established. Data flows are largely proportionate to Dependabot triage, yet the unresolved external binary trust and autonomous merge behavior raise the overall security risk.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Mar 26, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/delexw%2Fclaude-code-misc%2Fdependabot-merger%2F@9ff1fd3e34c2a604f71cd914eae86ff0b77110fe