skill-feedback

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core behavior is coherent: it gathers feedback and posts GitHub issues to the official target repo using GitHub's official CLI. The main concern is the anonymous path, which relies on a local unverified token-generation script and private key, then forwards the resulting credential to gh for external posting. That makes the skill high-risk from a credential-handling and trust perspective, though not clearly malicious.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 24, 2026, 12:44 PM
Package URL
pkg:socket/skills-sh/OntoLedgy%2Fol_ai_context_library%2Fskill-feedback%2F@6c37ef24a3df930880d3e61de99681e02f38dda1