github-multi-repo

Fail

Audited by Socket on Apr 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill’s core capabilities mostly match its stated multi-repo GitHub coordination purpose, and much of the GitHub CLI usage is legitimate. Risk comes from broad autonomous write actions across repositories, mutable `npx` execution, an unverified `gh-cli` dependency name, and an example that routes events/secrets to a third-party webhook endpoint. This looks like a high-impact automation skill with notable security risk, not confirmed malware.

Confidence: 84%Severity: 71%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:17 AM
Package URL
pkg:socket/skills-sh/dnyoussef%2Fai-chrome-extension%2Fgithub-multi-repo%2F@a368d3c944910c9c7adb76115dcf2157fd528d84