Verify Skill
Fail
Audited by Socket on Mar 2, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The code fragment describes a governance-oriented meta-skill intended to verify other skills and publish verification reports to GitHub Discussions. Its capabilities are coherent with the stated purpose, and it relies on legitimate tools (GitHub CLI) without embedding suspicious payloads. The primary security considerations are properly scoped to authentication and repository write access; if proper access controls are enforced and reviewers consent to publishing reports, the risk remains moderate. Recommend ensuring access is restricted to trusted maintainers, providing a local save option as a fallback, and auditing submission activities for traceability.
Confidence: 95%Severity: 90%
Audit Metadata