prd-to-prod-autopilot
Warn
Audited by Socket on Jul 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s orchestration scope mostly matches its stated PRD-to-PR purpose, but it grants broad autonomous GitHub actions and relies heavily on transitive sub-skill trust whose provenance and permissions are not provided. No direct malware or credential-stealing behavior is visible, but the combination of autonomous repo actions plus unverified dependent skills makes the overall security posture medium-high risk.
Confidence: 84%Severity: 72%
Audit Metadata