github

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The artifact is a legitimate GitHub automation skill, not directly malicious. However, it contains operational guidance that increases credential exposure risk—most notably instructing users to embed GITHUB_TOKEN in git remote URLs and mandating an unspecified create_pr tool without describing its trust boundary. Recommend removing the git remote set-url recommendation, adding explicit safe-carrying instructions (use gh auth, OS credential helpers, Authorization headers read from env, avoid command-line token embedding), require least-privilege tokens, and document how create_pr handles credentials and where it runs. With those mitigations the risk is low; as written, treat as moderate risk primarily due to credential leakage potential.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 07:40 PM
Package URL
pkg:socket/skills-sh/plurigrid%2Fasi%2Fgithub%2F@517255558c175692b7c50d384e71ea996c3480f5