ce-babysit-pr
Warn
Audited by Socket on Aug 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is purpose-aligned and uses mostly official GitHub tooling, so it does not look like credential theft or overt malware. However, it grants an AI agent a high-autonomy operational role over code, PR discussions, CI, and optional merging, while ingesting untrusted external content and delegating to other skills. That combination makes it a high security-risk automation skill even though its intent appears legitimate.
Confidence: 91%Severity: 78%
Audit Metadata