cmd-fix-pr-chechers
Warn
Audited by Socket on Apr 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's core capability fits its purpose and uses official GitHub tooling, but it grants an agent autonomous authority to change code, commit, and push repeatedly based on untrusted CI log content. The main risk is unintended or manipulated repository changes rather than malware or credential harvesting.
Confidence: 88%Severity: 72%
Audit Metadata