agent-issue-tracker

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill fragment is purpose-aligned and internally coherent: it describes a swarm-coordinated, automated GitHub issue management workflow with progress tracking and cross-repo synchronization. The data flows are appropriate for its purpose (GitHub API interactions and internal swarm memory). While the pattern is powerful and should be guarded by robust access control, there are no evident malicious actions or credential-harvesting patterns in the provided code. Overall risk is moderate, mainly due to potential misconfiguration or overuse of automated issue actions rather than any inherent malicious capability.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 04:33 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fagent-issue-tracker%2F@ebddf21d71ed888a8a91eec3ab85ecf8a18bab0f