github-copilot-sdk

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This manifest documents a legitimate Copilot SDK integration (not executable malware). However, the documentation promotes high-risk defaults: --allow-all tooling and auto_activate:true without clear permissioning, sandboxing, or secure auth guidance. These defaults create plausible paths for sensitive local data (files, repo contents, credentials) to be exfiltrated via tool handlers or misconfigured MCP endpoints. Recommend changing defaults to deny-by-default for potentially destructive tools, require explicit scope/consent for filesystem/git/network access, document secure auth flows and token handling for CLI/MCP connections, and ensure example endpoints are clearly marked as placeholders or validated official endpoints. Treat integrations as security-sensitive and apply host-level permission controls and input validation for all tool handlers.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 26, 2026, 08:33 AM
Package URL
pkg:socket/skills-sh/rysweet%2Famplihack%2Fgithub-copilot-sdk%2F@540b328c568893eb08798d91c9493103ae309f03