triage-issue

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated triage purpose and its tool/data flows are mostly GitHub-native, but it gives an AI agent high-impact autonomous abilities over a code repository while consuming untrusted issue content. The main risk is prompt-injection and unintended repository/public actions, not credential theft or malware.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Mar 17, 2026, 08:00 AM
Package URL
pkg:socket/skills-sh/max-sixty%2Fworktrunk%2Ftriage-issue%2F@b822e2241a73fb9c9251541258c33c31a86ed486