gh-pr-review-fix

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the purpose and GitHub-focused capabilities mostly align, but the skill depends on an unverifiable local binary and allows autonomous commit/push. The data flow to GitHub is proportionate, yet the hard-coded opaque executable and write/exec loop make this high security risk despite limited evidence of explicit malware.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 19, 2026, 04:56 AM
Package URL
pkg:socket/skills-sh/BjornMelin%2Fdev-skills%2Fgh-pr-review-fix%2F@44a866108be89d0ca68dd4f3fca94cdb19c18c08