oh-task

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow is purpose-aligned for repo task automation, but it grants an AI agent high-impact autonomous repository actions and mixes untrusted GitHub content with command/code execution. Main concern is operational autonomy and the unspecified trust boundary around `sg`, not clear credential theft or malware.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Mar 30, 2026, 05:16 PM
Package URL
pkg:socket/skills-sh/open-horizon-labs%2Fmiranda%2Foh-task%2F@a2842204d4ebe3e1d9b0e8c4337e3302a378cbc1