pr-autopilot

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and capabilities are internally aligned for a PR-autopilot skill, and external tool trust is mostly sound because it uses official GitHub tooling. The main risk is not malware but scope: it gives an AI agent autonomous write/exec and public-action authority over a repo while consuming untrusted PR content and potentially executing PR-controlled build scripts. Overall this is a coherent but high-risk automation skill that should be treated as dangerous in operation, especially on untrusted branches or fork PRs.

Confidence: 91%Severity: 79%
Audit Metadata
Analyzed At
Aug 18, 2026, 07:42 PM
Package URL
pkg:socket/skills-sh/donnfelker%2Floop-skills%2Fpr-autopilot%2F@3f744ff796bccc85220a3312e47e4f76e18f6b644d6c839a867989ba8906977a
Security Audit — socket — pr-autopilot