copilot-sdk
Fail
Audited by Socket on Mar 10, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The Copilot SDK skill content is coherent with a developer tooling/documentation focus. It outlines installation from official registries, multi-language support, and standard client-server interactions via a local CLI or server mode. There are no evident security weaknesses (e.g., unverifiable binaries, credential leakage patterns, or suspicious data exfiltration) based on the provided material. Overall, the footprint is benign and proportionate to its stated purpose as a development SDK guide; however, as with any SDK that touches external services (GitHub/MCP) and requires authentication, users should ensure proper secret management and minimize exposure in shared environments.
Confidence: 98%
Audit Metadata