Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
failThis skill provides powerful GitHub management capabilities but introduces significant security risks. It includes instructions to bypass organizational policy checks (JIRA enforcement) and is highly vulnerable to Indirect Prompt Injection. A malicious actor could embed instructions in Pull Requests or Issues that the agent might execute, leading to unauthorized code merges, secret modifications, or workflow triggers. The heavy use of shell pipes and xargs also increases the risk of command injection from untrusted data.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · No issues
Runlayer
warn5/6 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed