devpilot-scanning-repos

Warn

Audited by Socket on May 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in stated purpose and data flow, but HIGH-CAUTION operationally: the skill is coherent for repo auditing and GitHub issue filing, with no suspicious installer or credential-routing behavior. Its main risk is that it combines broad ingestion of untrusted repository/docs content with command execution and autonomous GitHub mutations, creating meaningful indirect prompt-injection and action-abuse exposure.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
May 4, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/siyuqian%2Fdevpilot%2Fdevpilot-scanning-repos%2F@225e612b5106d38be96c30a881eb46d65e3ce851