iStore Build OpenClash

PassAudited by VirusTotal on May 8, 2026.

Findings (1)

The skill requires the user to provide a GitHub Personal Access Token (PAT) with broad 'repo' permissions and uses it to modify repository files and security settings via the GitHub API (SKILL.md). Specifically, it automates the elevation of workflow permissions to 'read and write' and pushes a custom workflow file. While these actions are consistent with the stated purpose of automating OpenClash builds, the handling of high-privilege secrets and the modification of repository security configurations via an AI agent's execution environment pose a significant security risk.