bot-tasks

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is broadly coherent with its stated purpose of automated task handling via a team workflow driven by bot-owner directives. It appropriately anticipates triage, code changes, testing, and PR workflows, while requiring GitHub authentication and careful access control. However, the pattern enables significant automated real-world actions across multiple repositories, which elevates risk if misused or misconfigured. The most important mitigations are explicit per-action user confirmations, strong credential management, auditing of automated changes, and robust tests/rollbacks. Overall, the engagement is BENIGN with MEDIUM risk due to automation scope and credential exposure potential.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 07:16 AM
Package URL
pkg:socket/skills-sh/seabbs%2Fskills%2Fbot-tasks%2F@fa28d405191daf14c4d4837c059fbbce229234ba