github-project-automation

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment is coherently aligned with its stated purpose of automating GitHub Projects v2 creation and management from codebase analysis. It uses standard, trusted tooling (GitHub CLI and GraphQL) and implements safeguards (approval gates, rate limiting). The data flows and permissions are proportional to the task, and there are no evident malicious activities or exfiltration patterns. Overall, the artifact is BENIGN with a moderate securityRisk due to required GitHub token scopes and bulk-change capabilities, but no explicit malicious intent detected.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 03:07 PM
Package URL
pkg:socket/skills-sh/Hankanman%2Fclaude-config%2Fgithub-project-automation%2F@4712d61022de227499d87253e076b7b79edd5c6f