heyeddi-pr-respond
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose broadly matches PR-response automation, and its visible GitHub data flow is proportionate, but it enables autonomous commit/push/post actions without user confirmation and depends on several HeyEddi-specific helper commands whose provenance and behavior are not publicly verifiable from the provided evidence. This is high security risk from trust and autonomy, but not confirmed malware.
Confidence: 87%Severity: 78%
Audit Metadata