cmd-fix-pr-chechers

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's core capability fits its purpose and uses official GitHub tooling, but it grants an agent autonomous authority to change code, commit, and push repeatedly based on untrusted CI log content. The main risk is unintended or manipulated repository changes rather than malware or credential harvesting.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Apr 27, 2026, 07:43 AM
Package URL
pkg:socket/skills-sh/gsmlg-dev%2Fcode-agent%2Fcmd-fix-pr-chechers%2F@22ec558a145ca4b45fc182365fad8427016d33d5
Security Audit — socket — cmd-fix-pr-chechers