feature-video
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core workflow is coherent for a PR demo skill and GitHub data flows are proportionate, but it relies on a separate `agent-browser` skill/tool with unverified trust and introduces transitive-install risk plus browser-automation exposure. Not malicious on its face, but higher risk than a self-contained GitHub-only skill.
Confidence: 84%Severity: 63%
Audit Metadata