add-bot

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No code-level malware or obfuscated malicious payloads detected. The implementation uses standard tools and GitHub API calls to accomplish its task. The primary security risk is operational: this automation switches active gh authentication and grants push permissions without confirmation, validation, or documented credential handling. In shared or CI environments where seabbs credentials might be available, this could be abused to grant repository write access inadvertently. Recommend adding explicit validation, confirmation prompts, least-privilege guidance, and audit logging before using in automation.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/seabbs%2Fclaude-code-config%2Fadd-bot%2F@5c70eadb660b3370f45a25fad009b9219e3ce433