OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Warn3 providerslatest audit Apr 18, 2026
Independent checks from skills.sh's audit partners.
This skill automates the process of fixing GitHub issues by orchestrating sub-agents. Its primary security risk is Indirect Prompt Injection. Because the skill fetches untrusted issue descriptions from GitHub and includes them in prompts for agents that have repository write access and network capabilities, a malicious issue could potentially trick the agents into performing unauthorized operations, such as leaking the GitHub token or modifying code inappropriately.
Detected behaviors
No alerts
1 issue