gh-agent-task
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s purpose and GitHub-focused capabilities are broadly aligned, and the documented network destination is GitHub. However, the install target is an internal/unverifiable CLI extension that receives high-privilege GitHub tokens and can trigger autonomous repo changes, so this should be treated as suspicious/high-risk rather than benign.
Confidence: 82%Severity: 84%
Audit Metadata