github

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose is coherent for a GitHub management skill, and GITHUB_TOKEN access is expected. Risk comes from install/execution trust and unverifiable data flow: the skill uses a local Bun wrapper plus an embedded third-party mcporter path that does not match GitHub’s official MCP installation guidance, while the actual script is absent, so token routing and endpoint integrity cannot be confirmed.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Mar 23, 2026, 01:11 PM
Package URL
pkg:socket/skills-sh/L-yifan%2Fskills%2Fgithub%2F@408310c11f045b1c346e5f44a468636f37a969a3