pr-sweep
Warn
Audited by Socket on Aug 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and GitHub-focused capabilities are internally consistent, and its external tooling appears official. However, it grants an AI agent unattended authority to execute repo-defined scripts, push fixes, close PRs, and auto-merge code after reading untrusted PR content. This is proportionate to a PR automation skill but still high-risk due to autonomous real-world actions and prompt-injection exposure, not because of clear malware or credential theft.
Confidence: 84%Severity: 78%
Audit Metadata