gh-pr-review-fix
Warn
Audited by Socket on Mar 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the purpose and GitHub-focused capabilities mostly align, but the skill depends on an unverifiable local binary and allows autonomous commit/push. The data flow to GitHub is proportionate, yet the hard-coded opaque executable and write/exec loop make this high security risk despite limited evidence of explicit malware.
Confidence: 86%Severity: 72%
Audit Metadata