pull-request-review

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches the git/PR capabilities and official CLI usage, but the skill expands into high-risk territory by following arbitrary repository setup instructions, processing untrusted PR content with command execution available, and delegating to another skill. No clear credential theft or malicious exfiltration is present, but the review workflow is risky for an AI agent.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Mar 25, 2026, 04:42 AM
Package URL
pkg:socket/skills-sh/alexanderguy%2Fskills%2Fpull-request-review%2F@4573cc4de7c6cc7e80931927ec248a3c0e294926