self-improve

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core capabilities broadly match its stated purpose, and there is no strong evidence of credential theft or third-party data routing. However, it grants an AI agent a high degree of autonomous code execution and merge authority over a local repository, creating meaningful risk from unattended actions and from processing untrusted repository content with write/exec privileges.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:26 AM
Package URL
pkg:socket/skills-sh/zereight%2Fgitlab-mcp%2Fself-improve%2F@cb82fda34e46e274dc644f9836c279b30603dea4