ru

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core git/GitHub capabilities fit a repo-updater, and the installer appears same-org rather than an unrelated payload, but the skill’s actual footprint is broad and high-impact. It enables autonomous multi-repo code modification, pushes/releases, and issue/PR actions while consuming untrusted external content and executing local commands, making it a high-risk automation skill rather than a narrowly scoped updater.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Mar 24, 2026, 02:56 AM
Package URL
pkg:socket/skills-sh/dicklesworthstone%2Frepo_updater%2Fru%2F@5abcc6b8f76f8986c199f9fc401c7f044c3f86dd