github-ops

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This GitHub Ops skill and its documented commands are consistent with a legitimate bulk-issue management tool that uses the GitHub CLI and local markdown files. No explicit malicious network endpoints, credential exfiltration, or obfuscated code are present in the documentation. Primary concerns are operational: the use of PowerShell -ExecutionPolicy Bypass and running a user-scoped skill script without an integrity check. These increase supply-chain risk and warrant inspecting the actual publish_issues.ps1 script before executing it with bypassed execution policy. Recommend running with -DryRun and reviewing the script contents and any changes in the skills directory prior to full execution.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 07:45 PM
Package URL
pkg:socket/skills-sh/jstarfilms%2Fvibecode-protocol-suite%2Fgithub-ops%2F@5093aef2eac66e52d252002f385b3242549d4850