check-pr
Warn
Audited by Socket on May 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN in intent but HIGH-RISK operationally: the skill is coherent and uses official GitHub tooling/endpoints, yet it grants an agent the ability to act on untrusted PR content by editing code, pushing commits, and posting public GitHub actions without explicit per-action approval.
Confidence: 89%Severity: 78%
Audit Metadata