gh-issues

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s GitHub automation purpose is broadly coherent and its network/data flows stay on official GitHub endpoints, but it is high-risk because it reads raw tokens from local files, forwards them into git remote URLs, and enables autonomous external actions like pushes, PRs, review replies, and Telegram posts based on untrusted issue/review content. The biggest concern is operational scope and credential handling, not confirmed malware.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
Apr 24, 2026, 10:07 AM
Package URL
pkg:socket/skills-sh/steipete%2Fclawdis%2Fgh-issues%2F@a5c61e13c74bab0d200bfde42967878fdcc1b172