update-os-packages
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s capabilities mostly match its maintenance purpose, but it depends on an authenticated custom tool feed in a personal GitHub Packages namespace and instructs storing a token in clear text. Data flows are largely coherent and there is no strong evidence of credential harvesting or unrelated exfiltration, so this looks more like a medium-risk trust and credential-handling issue than malware.
Confidence: 85%Severity: 66%
Audit Metadata