github-sync-helper

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities broadly fit a Git/GitHub automation helper and data flows target official GitHub endpoints, so it is not fundamentally incompatible with its stated purpose. However, it enables destructive repo actions and autonomous GitHub-side operations, requires a token passed into an unseen local script, and has a small consistency gap because examples depend on gh despite not declaring it. Risk is medium due to hidden script trust and high-impact actions, not clear malware indicators.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 28, 2026, 11:50 AM
Package URL
pkg:socket/skills-sh/OpenMinis%2FMinisSkills%2Fgithub-sync-helper%2F@f6eb1c3e00029413828816097888236a68d023cf