gh

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The underlying GitHub CLI use is legitimate, but the skill is not internally clean: it markets itself as `gh` while directing execution through third-party x-cmd, installed via remote shell. The capabilities broadly fit GitHub workflow management, but the install and execution path is not proportionate to the stated purpose and creates unnecessary credential and supply-chain risk.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fgh%2F@4bcf5070d490289831c953ca265c873f50d52198