ce-babysit-pr

Warn

Audited by Socket on Aug 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and uses mostly official GitHub tooling, so it does not look like credential theft or overt malware. However, it grants an AI agent a high-autonomy operational role over code, PR discussions, CI, and optional merging, while ingesting untrusted external content and delegating to other skills. That combination makes it a high security-risk automation skill even though its intent appears legitimate.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
Aug 14, 2026, 03:41 PM
Package URL
pkg:socket/skills-sh/everyinc%2Fcompound-engineering-plugin%2Fce-babysit-pr%2F@9248884e6f92ee939881a30f0bd8c548f29d6b9d4a31be291f75c4fc8b67aa0a
Security Audit — socket — ce-babysit-pr