user-story-reviewer
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's GitHub-focused capabilities mostly match its stated review purpose, and its main external dependency (`gh`) is official. However, it is high-risk because it processes untrusted PR/issue content, checks out and may execute PR code locally, and can autonomously push, approve, or merge on the user's behalf via an unseen script.
Confidence: 88%Severity: 74%
Audit Metadata