review-prs

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent for a PR-review skill and external tooling appears to be official GitHub infrastructure, but the skill enables autonomous GitHub posting in auto mode and processes untrusted PR content through subagents before taking external actions. The biggest inconsistency is scope: the declared allowed-tools do not match the documented python execution and GitHub write operations.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
May 2, 2026, 06:16 PM
Package URL
pkg:socket/skills-sh/brave%2Fbrave-core%2Freview-prs%2F@199651076504cb527e1e3da4406641605d384f82