github-multi-repo
Audited by Socket on Feb 25, 2026
1 alert found:
MalwareThe code fragment describes a comprehensive, multi-repo automation skill intended for legitimate cross-repo coordination, dependency synchronization, and architectural governance. Its footprint—cloning/updating many repositories, running tests, and pushing PRs across org-wide repos—is coherent with the stated purpose but inherently high-impact. There are no hardcoded secrets or obviously malicious data exfiltration patterns; however, the capability to perform large-scale, automated mutations across multiple repos without per-action user prompts introduces significant risk if misused or if the environment is compromised. Overall, the behavior is best categorized as BENIGN with HIGH operational risk and requires strong safeguards (review gates, dry-runs, least-privilege credentials, and explicit approval workflows) to mitigate potential cascading effects. Security risk is elevated due to scope and automation intensity, but not evidence of malicious payloads.