kata-add-issue

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill implements local issue capture and optional GitHub syncing in a way that aligns with its stated purpose. There are no signs of obfuscation, hardcoded secrets, or supply-chain download-execute patterns. The primary security risks are accidental disclosure: committing sensitive planning content to the repository and uploading issue bodies to GitHub when github.enabled=true. These behaviors are expected for a sync feature but warrant user awareness and appropriate configuration (commit_docs flag, gitignore, and verifying gh authentication).

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 11:22 PM
Package URL
pkg:socket/skills-sh/gannonh%2Fkata-skills%2Fkata-add-issue%2F@6adbc685f285da69fbd5375d3741a5608fe2fbc0