fix-issues
Warn
Audited by Socket on Apr 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-aligned and uses official GitHub paths, so it is not malware-like, but it grants an AI agent high-impact autonomous repo actions and mixes untrusted external issue content with code execution and write access. The main risk is unsafe automation, not covert exfiltration or deceptive install behavior.
Confidence: 89%Severity: 76%
Audit Metadata