ghpm-shared

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The ghpm-shared reference constitutes a coherent, purpose-driven blueprint for managing GitHub Projects v2 workflows via ghpm. Its capabilities—config-driven startup, cache management, session lifecycle, error handling, and optional agent integrations—are proportionate to its stated aim of providing shared prerequisites and startup flow. Notable security-relevant considerations include automatic external cache fetches and token-based authentication flows; these introduce modest risk, particularly around data freshness vs. network exposure and potential credential handling in logs. Overall, the footprint is benign to modestly suspicious due to remote fetch and session data handling, but not malicious given its documented intent and limited surface area. SecurityRisk is elevated by the remote data fetch pattern and credential exposure risk, but remains in a manageable range if standard safeguards (trusted sources, minimal logging of secrets, clear prompts) are followed.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 05:20 PM
Package URL
pkg:socket/skills-sh/jackchuka%2Fghpm%2Fghpm-shared%2F@c407ca0aa21ec3e773c7ad2bdb514cdb308bdc79