kata-review-pull-requests

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core purpose matches PR review, and its GitHub CLI usage is proportionate, but it combines untrusted diff ingestion with subagent prompting, file modification, commits, issue creation, and optional PR merge. The biggest concern is indirect prompt injection from PR content leading to downstream actions; install-trust risk is moderate due to execution of unseen repo-local scripts, not external downloads.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Apr 10, 2026, 12:02 PM
Package URL
pkg:socket/skills-sh/gannonh%2Fkata-orchestrator%2Fkata-review-pull-requests%2F@a953b9443f508721f9e13a5a1d299368805a77f4