pr-review
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS but not malicious. The skill is broadly aligned with PR review, uses official GitHub tooling, and routes data to GitHub rather than a third-party proxy. The main risk is that it executes repository-defined code (`composer fix`) and analyzes untrusted PR content with command-capable sub-agents, which is a high-impact design for an AI skill even though it fits the stated purpose.
Confidence: 87%Severity: 72%
Audit Metadata