generate-bug-report

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s real behavior does not match its stated purpose: it performs no bug scan, uses an April 1 trigger, fabricates audit output, and sends repo metadata to an only partially verified external endpoint. There is no confirmed malware or credential theft, but the deception and external data flow make the skill high-risk and incoherent for a legitimate bug-report generator.

Confidence: 90%Severity: 79%
Audit Metadata
Analyzed At
Mar 31, 2026, 05:33 PM
Package URL
pkg:socket/skills-sh/getsentry%2Fsentry-for-ai%2Fgenerate-bug-report%2F@03972b0fae909d62b21709d8ca48ef70f52d3d91