pr-qa

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is largely aligned with its stated PR-QA purpose and uses official GitHub APIs, but it is operationally high-impact: it can take autonomous GitHub actions and acts on untrusted external review content while retaining code-write and command-exec capabilities. This makes it suspicious from a security-risk perspective, though not malicious; the biggest concerns are autonomy abuse and indirect prompt injection, with moderate installer trust risk around optional gitleaks installation paths.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Apr 8, 2026, 04:28 PM
Package URL
pkg:socket/skills-sh/accolver%2Fskill-maker%2Fpr-qa%2F@d95c0a4e8c317f04df8ccba51f595f2f5f331432
Security Audit — socket — pr-qa