triage-issue

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

该技能的核心用途与代码排查基本一致,但它要求代理在无用户审核的情况下直接创建 GitHub issue,属于高风险的自主外发行为。数据流主要指向 GitHub 官方服务,未见明显凭证窃取或第三方转发,因此更像高风险自动化技能而非恶意技能。

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Mar 26, 2026, 02:30 AM
Package URL
pkg:socket/skills-sh/ProgrammerAnthony%2FAnything-Extract%2Ftriage-issue%2F@43870749c4cc9135556c2c69f9311d97d225460e