reproduce-bug

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core bug-reproduction capabilities are broadly aligned with its stated purpose, but it mixes untrusted GitHub content ingestion, delegated tool use, and an instruction to post back to GitHub without an explicit approval gate. There is no strong malware signal or obvious exfiltration endpoint, but the autonomous external action and indirect prompt-injection exposure make it medium risk.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:21 AM
Package URL
pkg:socket/skills-sh/udecode%2Fbetter-convex%2Freproduce-bug%2F@430dda711ab03177e49802473897d34fd186003b