auto-submit

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches the behavior, but the skill is high risk because it authorizes autonomous repository modification, PR creation, and merge without explicit approval. The main concern is autonomy abuse and reliance on unseen downstream skills, not malware or credential theft in the provided snippet.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Apr 4, 2026, 05:31 PM
Package URL
pkg:socket/skills-sh/stablyai%2Forca%2Fauto-submit%2F@d84db629212b0684f9e6ba3213382e4046b0ffca