pr-review-fixer

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS rather than malicious. The core GitHub review/CI-fix workflow is purpose-aligned and uses official GitHub APIs, but the skill depends on an unverifiable `rune` CLI and grants broad autonomous repository actions including commenting, resolving threads, committing, and pushing. No direct credential theft or non-GitHub exfiltration is evident, but the external CLI trust gap and autonomous execution make the skill high risk.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
May 19, 2026, 10:27 AM
Package URL
pkg:socket/skills-sh/arjenschwarz%2Fagentic-coding%2Fpr-review-fixer%2F@3932c16adeac5c582bdc202fc2cb3591d96142ce
Security Audit — socket — pr-review-fixer