github-stars-organizer

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose matches the behavior—organizing GitHub stars via browser automation—but the skill's trust model is weakened by its dependency on a separate third-party `chrome-cdp` skill from a personal GitHub repo and by requiring Chrome remote debugging over an authenticated browser session. No clear credential-harvesting or exfiltration path is stated, so this is not confirmed malware, but it carries meaningful security risk from transitive trust and broad browser control.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 26, 2026, 02:22 AM
Package URL
pkg:socket/skills-sh/itechmeat%2Fllm-code%2Fgithub-stars-organizer%2F@a490fc13cda7e01f569c1234297282e070cc3d94