auto-submit
Warn
Audited by Socket on Apr 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose matches the behavior, but the skill is high risk because it authorizes autonomous repository modification, PR creation, and merge without explicit approval. The main concern is autonomy abuse and reliance on unseen downstream skills, not malware or credential theft in the provided snippet.
Confidence: 89%Severity: 78%
Audit Metadata