resolve-pr-parallel

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s GitHub-focused capabilities largely match its stated PR-resolution purpose, and data flow appears to stay within GitHub/git remotes. However, it enables autonomous repository actions, processes untrusted PR comments while modifying code, and relies on unseen local scripts and subordinate agents, making it medium-to-high risk despite no clear evidence of malware or credential theft.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Mar 23, 2026, 04:31 AM
Package URL
pkg:socket/skills-sh/everyinc%2Fcompound-engineering-plugin%2Fresolve-pr-parallel%2F@244baf5ad5335164dc59cb3fef8cad5452b2d3f2