gh-agent-task

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s purpose and GitHub-focused capabilities are broadly aligned, and the documented network destination is GitHub. However, the install target is an internal/unverifiable CLI extension that receives high-privilege GitHub tokens and can trigger autonomous repo changes, so this should be treated as suspicious/high-risk rather than benign.

Confidence: 82%Severity: 84%
Audit Metadata
Analyzed At
Mar 18, 2026, 01:28 AM
Package URL
pkg:socket/skills-sh/github%2Fgh-aw%2Fgh-agent-task%2F@50bd0c3f646bbeac767ea976d4416f4af0e66834