oh-notes

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core capabilities fit its stated purpose, and its primary data flows stay within GitHub/repo tooling. However, it grants an agent broad autonomous write actions (issue creation, commits, pushes, comment replies) while ingesting untrusted PR comments and invoking an external review tool, making it a high-impact automation skill rather than a benign documentation-style helper.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Mar 30, 2026, 05:16 PM
Package URL
pkg:socket/skills-sh/open-horizon-labs%2Fmiranda%2Foh-notes%2F@438b8e0f07bece4b12ee640a324c971c7aa56662