review-prs
Warn
Audited by Socket on May 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is coherent for a PR-review skill and external tooling appears to be official GitHub infrastructure, but the skill enables autonomous GitHub posting in auto mode and processes untrusted PR content through subagents before taking external actions. The biggest inconsistency is scope: the declared allowed-tools do not match the documented python execution and GitHub write operations.
Confidence: 85%Severity: 62%
Audit Metadata