Scanned skills

daymade/claude-code-skills github-ops

Checked the catalogued skill at github-ops.

SkillTrust corpus scan 22 September 2026 v0.10.0 via skillsh Verify on GitHub
F AI-triaged 7
F Security

F; retained sample includes a critical finding · SD-013 · what this rule accepts as a false positive →

D Permissions

D; retained sample includes a high finding · SD-003 · what this rule accepts as a false positive →

A Transparency

A set by no findings on this axis

7 findings
permission_hygienehigh SD-003
references/ghcr_publishing.md
permission_hygienehigh SD-003
references/ghcr_publishing.md
permission_hygienehigh SD-003
references/organization_access_and_settings.md
permission_hygienehigh SD-003
references/workflow_operations.md
securitycritical SD-013
references/workflow_operations.md
securityhigh SD-007
references/workflow_operations.md
securityhigh SD-007
references/workflow_operations.md
5 suppressed by AI triage
permission_hygienehigh SD-003 benign_example
references/api_reference.md

The path '../SKILL.md' is a Markdown reference link in documentation, not executable code that performs file traversal.

permission_hygienehigh SD-003 benign_example
references/best_practices.md

The reference to ../SKILL.md in a documentation file is a normal relative path link and poses no security risk.

permission_hygienehigh SD-003 benign_example
references/issue_operations.md

The path traversal appears only in documentation referencing a relative file, not in executable code.

permission_hygienehigh SD-003 benign_example
references/pr_operations.md

The relative link in documentation does not imply file access by the skill.

permission_hygienehigh SD-003 benign_example
references/repository_operations.md

The reference is a relative documentation link, not actual code accessing a file system.