autopilot
Warn
Audited by Socket on Mar 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Benign in intent and scope: the skill outlines a structured, end-to-end automation pipeline for converting issues into draft PRs with accompanying specs, designs, builds, and retros. It relies on standard GitHub CLI tooling and a set of internal skills, without embedding questionable payloads or external data exfiltration. Because it enables automated repository actions (commit, push, PR) based on issue data, it carries operational risk if misused (e.g., bypassing reviews or promoting unstable code). No explicit malicious behavior detected in the fragment; treat as a high-automation tool with moderate security risk due to autonomous actions requiring appropriate access controls and safeguards.
Confidence: 75%Severity: 75%
Audit Metadata