reproduce

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent, but the skill gives an agent authority to ingest untrusted GitHub issue content and repository instructions, then execute build/start workflows in the local environment. There is no direct credential harvesting or explicit exfiltration path, yet the combination of external content plus command execution makes this a medium-risk debugging skill rather than a benign documentation-only skill.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 7, 2026, 08:10 AM
Package URL
pkg:socket/skills-sh/Tharsanan1%2Fwso2-se-agent-skills%2Freproduce%2F@9f90ffbda4f28875bf20ee6c6b7942e08ba7d84f