engram-backlog-triage
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is coherent for GitHub triage and uses the official GitHub CLI, but it grants an agent the ability to autonomously review, close, label, and merge based on untrusted GitHub content. The main risk is unsafe autonomous repository actions and prompt-injection exposure, not malware or credential theft.
Confidence: 89%Severity: 72%
Audit Metadata