ghpm-work

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the ghpm-work skill appears benign and proportionate to its stated purpose. It leverages standard development tooling (gh CLI, git), maintains explicit per-phase session state, and interacts with GitHub through authenticated API calls as part of a documented workflow. No evident credential harvesting, unverified binaries, or covert data exfiltration patterns are observed. As with any automation that handles project data and GitHub interactions, ensure proper local access controls for session files and restrict gh API scopes to the minimum required actions.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:36 AM
Package URL
pkg:socket/skills-sh/jackchuka%2Fghpm%2Fghpm-work%2F@a92949bea08d644c06d79a2914f7101cb9d3a6e7