github

Fail

Audited by Socket on Mar 7, 2026

2 alerts found:

Obfuscated Filex2
Obfuscated FileHIGH
SKILL.md

The GitHub Skill presents a coherent and proportionate toolset for performing GitHub operations via Python scripts with structured output. The footprint is consistent with the stated purpose (avoid raw gh, provide robust output and error handling). The main security considerations hinge on credential management (tokens needed to access GitHub) and dependency provenance. No evident download-execute supply chain or credential-forwarding to unknown binaries is described. Overall, the skill appears benign to moderately risky (expected credential handling and mutating GitHub actions), deserving normal trust with proper credential governance and dependency sourcing.

Confidence: 98%
Obfuscated FileHIGH
fix-ci.md

No explicit malware or obfuscated payloads found in this skill specification. The primary security concern is the autonomous commit-and-push behavior without approval or path restrictions, and the execution of repository code during local validation — both create supply-chain risks that could be abused to inject malicious code or leak secrets. Recommend mitigating controls: require human approval for pushes to protected branches, restrict editable file paths, use least-privilege tokens, add commit review/audit logging, and sanitize or sandbox local validation execution.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/rjmurillo%2Fai-agents%2Fgithub%2F@36340103c7bbdcd341d5fa9c83d0ac26d3ad935b