resolve-pr-parallel
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s GitHub-focused capabilities largely match its stated PR-resolution purpose, and data flow appears to stay within GitHub/git remotes. However, it enables autonomous repository actions, processes untrusted PR comments while modifying code, and relies on unseen local scripts and subordinate agents, making it medium-to-high risk despite no clear evidence of malware or credential theft.
Confidence: 86%Severity: 68%
Audit Metadata