babysit
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is purpose-aligned for PR babysitting and its main external tooling is official GitHub/git, with no clear credential theft or off-platform exfiltration. However, it grants an agent broad unattended authority to edit code, resolve conflicts, force-push, rerun CI, manage scheduled tasks, and delegate to another unreviewed skill, making it a high operational-risk automation skill even without evidence of malware.
Confidence: 85%Severity: 76%
Audit Metadata