autopilot

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Benign in intent and scope: the skill outlines a structured, end-to-end automation pipeline for converting issues into draft PRs with accompanying specs, designs, builds, and retros. It relies on standard GitHub CLI tooling and a set of internal skills, without embedding questionable payloads or external data exfiltration. Because it enables automated repository actions (commit, push, PR) based on issue data, it carries operational risk if misused (e.g., bypassing reviews or promoting unstable code). No explicit malicious behavior detected in the fragment; treat as a high-automation tool with moderate security risk due to autonomous actions requiring appropriate access controls and safeguards.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 04:04 AM
Package URL
pkg:socket/skills-sh/phrazzld%2Fclaude-config%2Fautopilot%2F@08ce23722a670836b948183b515304e24733470d